Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown

CVE-2016-3738

Disclosure Date: June 08, 2016 (last updated November 25, 2024)
Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-pod.
0
Attacker Value
Unknown

CVE-2016-3703

Disclosure Date: June 08, 2016 (last updated November 25, 2024)
Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod, which allows remote attackers to access API credentials in the web browser localStorage via an access_token in the query parameter.
0
Attacker Value
Unknown

CVE-2016-3708

Disclosure Date: June 08, 2016 (last updated November 25, 2024)
Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in other namespaces, allows remote authenticated users to access network resources on restricted pods via an s2i build with a builder image that (1) contains ONBUILD commands or (2) does not contain a tar binary.
0
Attacker Value
Unknown

CVE-2016-3725

Disclosure Date: May 17, 2016 (last updated November 25, 2024)
Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of update site metadata by leveraging a missing permissions check. NOTE: this issue can be combined with DNS cache poisoning to cause a denial of service (service disruption).
0
Attacker Value
Unknown

CVE-2016-3727

Disclosure Date: May 17, 2016 (last updated November 25, 2024)
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-3722

Disclosure Date: May 17, 2016 (last updated November 25, 2024)
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the "full name."
0
Attacker Value
Unknown

CVE-2016-3724

Disclosure Date: May 17, 2016 (last updated November 25, 2024)
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.
0
Attacker Value
Unknown

CVE-2016-3721

Disclosure Date: May 17, 2016 (last updated May 03, 2024)
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
0
Attacker Value
Unknown

CVE-2016-3726

Disclosure Date: May 17, 2016 (last updated November 25, 2024)
Multiple open redirect vulnerabilities in Jenkins before 2.3 and LTS before 1.651.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors related to "scheme-relative" URLs.
0
Attacker Value
Unknown

CVE-2016-3723

Disclosure Date: May 17, 2016 (last updated November 25, 2024)
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
0