Show filters
240 Total Results
Displaying 81-90 of 240
Sort by:
Attacker Value
Unknown

CVE-2018-1999036

Disclosure Date: August 01, 2018 (last updated November 27, 2024)
An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the SSH private key password to users with permission to read the build log.
0
Attacker Value
Unknown

CVE-2017-2648

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.
0
Attacker Value
Unknown

CVE-2018-14441

Disclosure Date: July 20, 2018 (last updated November 27, 2024)
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. admin/admin/fileUploadAction_fileUpload.action allows arbitrary file upload, as demonstrated by a .jsp file with the image/jpeg content type.
0
Attacker Value
Unknown

CVE-2018-14440

Disclosure Date: July 20, 2018 (last updated November 27, 2024)
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. SQL injection exists via the admin/noticeManageAction_queryNotice.action noticeInfo parameter.
0
Attacker Value
Unknown

CVE-2018-1000601

Disclosure Date: June 26, 2018 (last updated November 26, 2024)
A arbitrary file read vulnerability exists in Jenkins SSH Credentials Plugin 1.13 and earlier in BasicSSHUserPrivateKey.java that allows attackers with a Jenkins account and the permission to configure credential bindings to read arbitrary files from the Jenkins master file system.
0
Attacker Value
Unknown

CVE-2018-7749

Disclosure Date: March 12, 2018 (last updated November 08, 2023)
The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step.
0
Attacker Value
Unknown

CVE-2016-10708

Disclosure Date: January 21, 2018 (last updated November 08, 2023)
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.
0
Attacker Value
Unknown

CVE-2017-1000245

Disclosure Date: November 01, 2017 (last updated November 26, 2024)
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.
0
Attacker Value
Unknown

CVE-2017-15906

Disclosure Date: October 26, 2017 (last updated November 26, 2024)
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
Attacker Value
Unknown

CVE-2017-9078

Disclosure Date: May 19, 2017 (last updated November 26, 2024)
The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled.