Show filters
48 Total Results
Displaying 41-48 of 48
Sort by:
Attacker Value
Unknown
CVE-2020-4092
Disclosure Date: May 06, 2020 (last updated February 21, 2025)
"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can potentially expose sensitive information including but not limited to server names, user IDs and document content."
0
Attacker Value
Unknown
CVE-2020-10944
Disclosure Date: April 28, 2020 (last updated February 21, 2025)
HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fixed in 0.10.5.
0
Attacker Value
Unknown
CVE-2020-10257
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
0
Attacker Value
Unknown
CVE-2020-7218
Disclosure Date: January 31, 2020 (last updated February 21, 2025)
HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 0.10.3.
0
Attacker Value
Unknown
CVE-2020-7956
Disclosure Date: January 31, 2020 (last updated February 21, 2025)
HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.
0
Attacker Value
Unknown
CVE-2019-12618
Disclosure Date: August 12, 2019 (last updated November 27, 2024)
HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.
0
Attacker Value
Unknown
CVE-2019-1003092
Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A cross-site request forgery vulnerability in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
0
Attacker Value
Unknown
CVE-2019-1003093
Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
0