Show filters
49 Total Results
Displaying 11-20 of 49
Sort by:
Attacker Value
Unknown

CVE-2023-33005

Disclosure Date: May 16, 2023 (last updated October 08, 2023)
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not invalidate the previous session on login.
Attacker Value
Unknown

CVE-2023-30528

Disclosure Date: April 12, 2023 (last updated October 08, 2023)
Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it.
Attacker Value
Unknown

CVE-2023-30527

Disclosure Date: April 12, 2023 (last updated October 08, 2023)
Jenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2023-1093

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The OAuth Single Sign On WordPress plugin before 6.24.2 does not have CSRF checks when discarding Identify providers (IdP), which could allow attackers to make logged in admins delete all IdP via a CSRF attack
Attacker Value
Unknown

CVE-2023-1092

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The OAuth Single Sign On Free WordPress plugin before 6.24.2, OAuth Single Sign On Standard WordPress plugin before 28.4.9, OAuth Single Sign On Premium WordPress plugin before 38.4.9 and OAuth Single Sign On Enterprise WordPress plugin before 48.4.9 do not have CSRF checks when deleting Identity Providers (IdP), which could allow attackers to make logged in admins delete arbitrary IdP via a CSRF attack
Attacker Value
Unknown

CVE-2022-4148

Disclosure Date: March 20, 2023 (last updated October 08, 2023)
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.
Attacker Value
Unknown

CVE-2022-3894

Disclosure Date: March 20, 2023 (last updated October 08, 2023)
The WP OAuth Server (OAuth Authentication) WordPress plugin before 4.2.5 does not have CSRF check when deleting a client, and does not ensure that the object to be deleted is actually a client, which could allow attackers to make a logged in admin delete arbitrary client and post via a CSRF attack.
Attacker Value
Unknown

CVE-2023-24428

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.
Attacker Value
Unknown

CVE-2023-24427

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.
Attacker Value
Unknown

CVE-2020-36569

Disclosure Date: December 27, 2022 (last updated October 08, 2023)
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.