Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown
CVE-2024-45247
Disclosure Date: October 06, 2024 (last updated October 07, 2024)
Sonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
0
Attacker Value
Unknown
CVE-2024-7694
Disclosure Date: August 12, 2024 (last updated September 07, 2024)
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.
0
Attacker Value
Unknown
CVE-2024-38460
Disclosure Date: June 16, 2024 (last updated August 08, 2024)
In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as SonarQube Access Logs, Proxy Logs, etc).
0
Attacker Value
Unknown
CVE-2023-35145
Disclosure Date: June 14, 2023 (last updated October 08, 2023)
Jenkins Sonargraph Integration Plugin 5.0.1 and earlier does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission.
0
Attacker Value
Unknown
CVE-2022-45213
Disclosure Date: January 01, 2023 (last updated October 08, 2023)
perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL.
0
Attacker Value
Unknown
CVE-2022-45027
Disclosure Date: January 01, 2023 (last updated October 08, 2023)
perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determine a local address.
0
Attacker Value
Unknown
CVE-2022-46688
Disclosure Date: December 12, 2022 (last updated October 25, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins connect to Gerrit servers (previously configured by Jenkins administrators) using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2022-41413
Disclosure Date: November 30, 2022 (last updated October 08, 2023)
perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attacker injects crafted input into the Search function.
0
Attacker Value
Unknown
CVE-2022-41412
Disclosure Date: November 30, 2022 (last updated October 08, 2023)
An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.
0
Attacker Value
Unknown
CVE-2020-28443
Disclosure Date: July 25, 2022 (last updated October 07, 2023)
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
0