Show filters
402 Total Results
Displaying 101-110 of 402
Sort by:
Attacker Value
Unknown
CVE-2023-0044
Disclosure Date: February 23, 2023 (last updated February 24, 2025)
If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Information Disclosure. This attack can be prevented with the Quarkus CSRF Prevention feature.
0
Attacker Value
Unknown
CVE-2022-4492
Disclosure Date: February 23, 2023 (last updated October 08, 2023)
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
0
Attacker Value
Unknown
CVE-2023-25762
Disclosure Date: February 15, 2023 (last updated February 24, 2025)
Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pipeline Snippet Generator, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control job names.
0
Attacker Value
Unknown
CVE-2022-3241
Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
0
Attacker Value
Unknown
CVE-2022-46686
Disclosure Date: December 12, 2022 (last updated February 24, 2025)
Jenkins Custom Build Properties Plugin 2.79.vc095ccc85094 and earlier does not escape property values and build display names on the Custom Build Properties and Build Summary pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set or change these values.
0
Attacker Value
Unknown
CVE-2022-4116
Disclosure Date: November 22, 2022 (last updated October 08, 2023)
A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.
0
Attacker Value
Unknown
CVE-2022-42202
Disclosure Date: October 18, 2022 (last updated February 24, 2025)
TP-Link TL-WR841N 8.0 4.17.16 Build 120201 Rel.54750n is vulnerable to Cross Site Scripting (XSS).
0
Attacker Value
Unknown
CVE-2022-41232
Disclosure Date: September 21, 2022 (last updated February 24, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers to replace any config.xml file on the Jenkins controller file system with an empty file by providing a crafted file name to an API endpoint.
0
Attacker Value
Unknown
CVE-2022-41231
Disclosure Date: September 21, 2022 (last updated February 24, 2025)
Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on the Jenkins controller file system by providing a crafted file name to an API endpoint.
0
Attacker Value
Unknown
CVE-2022-41230
Disclosure Date: September 21, 2022 (last updated February 24, 2025)
Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish builds to, as well as builds pending for publication to those Jenkins servers.
0