Show filters
240 Total Results
Displaying 41-50 of 240
Sort by:
Attacker Value
Unknown

CVE-2022-30957

Disclosure Date: May 17, 2022 (last updated October 25, 2023)
A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2022-27191

Disclosure Date: March 18, 2022 (last updated November 08, 2023)
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
Attacker Value
Unknown

CVE-2021-36368

Disclosure Date: March 13, 2022 (last updated November 08, 2023)
An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None authentication option, then the user cannot determine whether FIDO authentication is going to confirm that the user wishes to connect to that server, or that the user wishes to allow that server to connect to a different server on the user's behalf. NOTE: the vendor's position is "this is not an authentication bypass, since nothing is being bypassed.
Attacker Value
Unknown

CVE-2022-23114

Disclosure Date: January 12, 2022 (last updated October 25, 2023)
Jenkins Publish Over SSH Plugin 1.22 and earlier stores password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-23113

Disclosure Date: January 12, 2022 (last updated October 25, 2023)
Jenkins Publish Over SSH Plugin 1.22 and earlier performs a validation of the file name specifying whether it is present or not, resulting in a path traversal vulnerability allowing attackers with Item/Configure permission to discover the name of the Jenkins controller files.
Attacker Value
Unknown

CVE-2022-23112

Disclosure Date: January 12, 2022 (last updated October 25, 2023)
A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access to connect to an attacker-specified SSH server using attacker-specified credentials.
Attacker Value
Unknown

CVE-2022-23111

Disclosure Date: January 12, 2022 (last updated October 25, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.
Attacker Value
Unknown

CVE-2022-23110

Disclosure Date: January 12, 2022 (last updated October 25, 2023)
Jenkins Publish Over SSH Plugin 1.22 and earlier does not escape the SSH server name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.
Attacker Value
Unknown

CVE-2022-20620

Disclosure Date: January 12, 2022 (last updated October 25, 2023)
Missing permission checks in Jenkins SSH Agent Plugin 1.23 and earlier allows attackers with Overall/Read access to enumerate credentials IDs of credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2021-45099

Disclosure Date: December 16, 2021 (last updated November 08, 2023)
The addon.stdin service in addon-ssh (aka Home Assistant Community Add-on: SSH & Web Terminal) before 10.0.0 has an attack surface that requires social engineering. NOTE: the vendor does not agree that this is a vulnerability; however, addon.stdin was removed as a defense-in-depth measure against complex social engineering situations