Show filters
133 Total Results
Displaying 51-60 of 133
Sort by:
Attacker Value
Unknown

CVE-2019-10383

Disclosure Date: August 28, 2019 (last updated October 26, 2023)
A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.
Attacker Value
Unknown

CVE-2019-9514

Disclosure Date: August 13, 2019 (last updated January 15, 2025)
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.
Attacker Value
Unknown

CVE-2019-11250

Disclosure Date: August 12, 2019 (last updated November 27, 2024)
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.
Attacker Value
Unknown

CVE-2019-10176

Disclosure Date: August 02, 2019 (last updated November 27, 2024)
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.
0
Attacker Value
Unknown

CVE-2019-10356

Disclosure Date: July 31, 2019 (last updated October 26, 2023)
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method pointer expressions allowed attackers to execute arbitrary code in sandboxed scripts.
Attacker Value
Unknown

CVE-2019-10355

Disclosure Date: July 31, 2019 (last updated October 26, 2023)
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary code in sandboxed scripts.
Attacker Value
Unknown

CVE-2019-10357

Disclosure Date: July 31, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by global libraries.
Attacker Value
Unknown

CVE-2019-1010238

Disclosure Date: July 19, 2019 (last updated November 08, 2023)
Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to functions like pango_itemize.
Attacker Value
Unknown

CVE-2019-10354

Disclosure Date: July 17, 2019 (last updated October 26, 2023)
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
Attacker Value
Unknown

CVE-2018-11307

Disclosure Date: July 09, 2019 (last updated November 08, 2023)
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.