Show filters
542 Total Results
Displaying 291-300 of 542
Sort by:
Attacker Value
Unknown
CVE-2019-12156
Disclosure Date: October 02, 2019 (last updated November 27, 2024)
Server metadata could be exposed because one of the error messages reflected the whole response back to the client in JetBrains TeamCity versions before 2018.2.5 and UpSource versions before 2018.2 build 1293.
0
Attacker Value
Unknown
CVE-2019-12157
Disclosure Date: October 02, 2019 (last updated November 27, 2024)
In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.
0
Attacker Value
Unknown
CVE-2019-14961
Disclosure Date: October 01, 2019 (last updated November 27, 2024)
JetBrains Upsource before 2019.1.1412 was not properly escaping HTML tags in a code block comments, leading to XSS.
0
Attacker Value
Unknown
CVE-2019-10435
Disclosure Date: October 01, 2019 (last updated October 26, 2023)
Jenkins SourceGear Vault Plugin transmits configured credentials in plain text as part of job configuration forms, potentially resulting in their exposure.
0
Attacker Value
Unknown
CVE-2019-16188
Disclosure Date: September 25, 2019 (last updated November 27, 2024)
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a specially crafted .ozasmt file to a targeted victim and ask the victim to open it. When the victim imports the .ozasmt file in AppScan Source, the content of any file in the local file system (to which the victim as read access) can be exfiltrated to a remote listener under the attacker's control. The product does not disable external XML Entity Processing, which can lead to information disclosure and denial of services attacks.
0
Attacker Value
Unknown
CVE-2018-18863
Disclosure Date: June 19, 2019 (last updated November 27, 2024)
NGA ResourceLink 20.0.2.1 allows local file inclusion.
0
Attacker Value
Unknown
CVE-2019-11582
Disclosure Date: June 14, 2019 (last updated November 27, 2024)
An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, allows remote attackers to gain remote code execution through the use of a crafted URI.
0
Attacker Value
Unknown
CVE-2019-10338
Disclosure Date: June 11, 2019 (last updated October 26, 2023)
A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed attackers to have Jenkins connect to an attacker-specified Kubernetes server, potentially leaking credentials.
0
Attacker Value
Unknown
CVE-2019-10339
Disclosure Date: June 11, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguration#doValidateClient allowed users with Overall/Read access to have Jenkins connect to an attacker-specified Kubernetes server, potentially leaking credentials.
0
Attacker Value
Unknown
CVE-2019-0227
Disclosure Date: May 01, 2019 (last updated November 08, 2023)
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
0