|
CVE-2020-24616
|
High
|
2020-08-25
|
Mitigation candidate
|
No public exploit
|
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
|
|
CVE-2020-2231
|
Medium
|
2020-08-12
|
Mitigation candidate
|
Working exploit published
|
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
|
|
CVE-2020-2230
|
Medium
|
2020-08-12
|
Mitigation candidate
|
Working exploit published
|
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.
|
|
CVE-2020-2229
|
Medium
|
2020-08-12
|
Mitigation candidate
|
Working exploit published
|
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.
|
|
CVE-2020-5412
|
Medium
|
2020-08-07
|
Mitigation candidate
|
Working exploit published
|
Spring Cloud Netflix, versions 2.2.x prior to 2.2.4, versions 2.1.x prior to 2.1.6, and older unsupported versions allow applications to use the Hystrix Dashboard proxy.stream endpoint to make requests to any server reachable by the server hosting the dashboard. A malicious user, or attacker, can send a request to other servers that should not be exposed publicly.
|