Show filters
49 Total Results
Displaying 11-20 of 49
Sort by:
Attacker Value
Unknown
CVE-2023-33005
Disclosure Date: May 16, 2023 (last updated October 08, 2023)
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.
0
Attacker Value
Unknown
CVE-2023-30528
Disclosure Date: April 12, 2023 (last updated October 08, 2023)
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it.
0
Attacker Value
Unknown
CVE-2023-30527
Disclosure Date: April 12, 2023 (last updated October 08, 2023)
Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2023-1093
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack
0
Attacker Value
Unknown
CVE-2023-1092
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-4148
Disclosure Date: March 20, 2023 (last updated October 08, 2023)
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.
0
Attacker Value
Unknown
CVE-2022-3894
Disclosure Date: March 20, 2023 (last updated October 08, 2023)
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.
0
Attacker Value
Unknown
CVE-2023-24428
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.
0
Attacker Value
Unknown
CVE-2023-24427
Disclosure Date: January 26, 2023 (last updated October 08, 2023)
Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.
0
Attacker Value
Unknown
CVE-2020-36569
Disclosure Date: December 27, 2022 (last updated October 08, 2023)
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.
0