|
CVE-2020-9447
|
Medium
|
2020-02-28
|
No exploit published
|
No public exploit
|
There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can upload a file with a malicious filename, which contains JavaScript code, which would result in XSS. Cross-site scripting enables attackers to steal data, change the appearance of a website, and perform other malicious activities like phishing or drive-by hacking.
|
|
CVE-2015-2992
|
Medium
|
2020-02-27
|
No exploit published
|
No public exploit
|
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
|
|
CVE-2020-5245
|
High
|
2020-02-24
|
No exploit published
|
Proof of concept only
|
Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature.
The issue has been fixed in dropwizard-validation 1.3.19 and 2.0.2.
|
|
CVE-2020-1938
|
Critical
|
2020-02-24
|
Protected by RASP
|
Exploited in the wild
|
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
|
|
CVE-2020-1937
|
High
|
2020-02-24
|
Protected by RASP
|
No public exploit
|
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.
|
|
CVE-2020-1935
|
Medium
|
2020-02-24
|
No exploit published
|
No public exploit
|
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
|
|
CVE-2012-0785
|
High
|
2020-02-24
|
No exploit published
|
No public exploit
|
Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."
|
|
CVE-2020-8441
|
Critical
|
2020-02-19
|
Protected by RASP
|
No public exploit
|
JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function. NOTE: this is a discontinued product.
|
|
CVE-2019-10797
|
Medium
|
2020-02-19
|
No exploit published
|
No public exploit
|
Netty in WSO2 transport-http before v6.3.1 is vulnerable to HTTP Response Splitting due to HTTP Header validation being disabled.
|
|
CVE-2020-2133
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
|
|
CVE-2020-2132
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
|
|
CVE-2020-2131
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
|
|
CVE-2020-2130
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins Harvest SCM Plugin 0.5.1 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
|
|
CVE-2020-2129
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
|
|
CVE-2020-2128
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins ECX Copy Data Management Plugin 1.9 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
|
|
CVE-2020-2127
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
|
|
CVE-2020-2126
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins master where it can be viewed by users with access to the master file system.
|
|
CVE-2020-2125
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins Debian Package Builder Plugin 1.6.11 and earlier stores a GPG passphrase unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
|
|
CVE-2020-2124
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
|
|
CVE-2020-2123
|
High
|
2020-02-12
|
Protected by RASP
|
No public exploit
|
Jenkins RadarGun Plugin 1.7 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
|
|
CVE-2020-2122
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins Brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site scripting vulnerability exploitable by users able to control the Brakeman post-build step input data.
|
|
CVE-2020-2121
|
High
|
2020-02-12
|
Protected by RASP
|
No public exploit
|
Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
|
|
CVE-2020-2120
|
High
|
2020-02-12
|
Protected by RASP
|
No public exploit
|
Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
|
|
CVE-2020-2119
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
|
|
CVE-2020-2118
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
|
|
CVE-2020-2117
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
|
|
CVE-2020-2116
|
High
|
2020-02-12
|
No exploit published
|
No public exploit
|
A cross-site request forgery vulnerability in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
|
|
CVE-2020-2115
|
High
|
2020-02-12
|
Protected by RASP
|
No public exploit
|
Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
|
|
CVE-2020-2114
|
High
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
|
|
CVE-2020-2113
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.
|
|
CVE-2020-2112
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.
|
|
CVE-2020-2111
|
Medium
|
2020-02-12
|
No exploit published
|
No public exploit
|
Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability.
|
|
CVE-2020-2110
|
High
|
2020-02-12
|
No exploit published
|
No public exploit
|
Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.
|
|
CVE-2020-2109
|
High
|
2020-02-12
|
No exploit published
|
No public exploit
|
Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter expressions in CPS-transformed methods.
|
|
CVE-2014-9390
|
Critical
|
2020-02-12
|
No exploit published
|
Forecast only
|
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.
|
|
CVE-2020-1942
|
High
|
2020-02-11
|
No exploit published
|
No public exploit
|
In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join a cluster and the cluster flow was not inheritable, the flow fingerprint of both the cluster and local flow was printed, potentially containing sensitive values in plaintext.
|
|
CVE-2020-8840
|
Critical
|
2020-02-10
|
Mitigation candidate
|
Proof of concept only
|
FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.
|
|
CVE-2020-1697
|
Medium
|
2020-02-10
|
No exploit published
|
No public exploit
|
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.
|
|
CVE-2019-4670
|
Medium
|
2020-02-05
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper data representation. IBM X-Force ID: 171319.
|
|
CVE-2020-4163
|
High
|
2020-02-04
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0, under specialized conditions, could allow an authenticated user to create a maliciously crafted file name which would be misinterpreted as jsp content and executed. IBM X-Force ID: 174397.
|