Show filters
168 Total Results
Displaying 21-30 of 168
Sort by:
Attacker Value
Unknown
CVE-2023-50773
Disclosure Date: December 13, 2023 (last updated December 19, 2023)
Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
0
Attacker Value
Unknown
CVE-2023-50772
Disclosure Date: December 13, 2023 (last updated December 19, 2023)
Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2023-48238
Disclosure Date: November 17, 2023 (last updated November 30, 2023)
joaquimserafim/json-web-token is a javascript library use to interact with JSON Web Tokens (JWT) which are a compact URL-safe means of representing claims to be transferred between two parties. Affected versions of the json-web-token library are vulnerable to a JWT algorithm confusion attack. On line 86 of the 'index.js' file, the algorithm to use for verifying the signature of the JWT token is taken from the JWT token, which at that point is still unverified and thus shouldn't be trusted. To exploit this vulnerability, an attacker needs to craft a malicious JWT token containing the HS256 algorithm, signed with the public RSA key of the victim application. This attack will only work against this library is the RS256 algorithm is in use, however it is a best practice to use that algorithm.
0
Attacker Value
Unknown
CVE-2023-5072
Disclosure Date: October 12, 2023 (last updated May 21, 2024)
Denial of Service in JSON-Java versions up to and including 20230618. A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.
0
Attacker Value
Unknown
CVE-2023-39685
Disclosure Date: September 01, 2023 (last updated October 08, 2023)
An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string.
0
Attacker Value
Unknown
CVE-2022-25024
Disclosure Date: August 22, 2023 (last updated October 08, 2023)
The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can lead to an exception, causing a denial of service.
0
Attacker Value
Unknown
CVE-2021-32292
Disclosure Date: August 22, 2023 (last updated October 08, 2023)
An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
0
Attacker Value
Unknown
CVE-2023-35110
Disclosure Date: June 14, 2023 (last updated October 08, 2023)
An issue was discovered jjson thru 0.1.7 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
0
Attacker Value
Unknown
CVE-2023-34620
Disclosure Date: June 14, 2023 (last updated October 08, 2023)
An issue was discovered hjson thru 3.0.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
0
Attacker Value
Unknown
CVE-2023-34616
Disclosure Date: June 14, 2023 (last updated October 08, 2023)
An issue was discovered pbjson thru 0.4.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
0