Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2014-125041

Disclosure Date: January 05, 2023 (last updated October 20, 2023)
A vulnerability classified as critical was found in Miccighel PR-CWT. This vulnerability affects unknown code. The manipulation leads to sql injection. The patch is identified as e412127d07004668e5a213932c94807d87067a1f. It is recommended to apply a patch to fix this issue. VDB-217486 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2019-10412

Disclosure Date: September 25, 2019 (last updated October 26, 2023)
Jenkins Inedo ProGet Plugin 1.2 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
Attacker Value
Unknown

CVE-2017-15608

Disclosure Date: September 26, 2018 (last updated November 27, 2024)
Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
0
Attacker Value
Unknown

CVE-2018-1999034

Disclosure Date: August 01, 2018 (last updated November 27, 2024)
A man in the middle vulnerability exists in Jenkins Inedo ProGet Plugin 0.8 and earlier in ProGetApi.java, ProGetConfig.java, ProGetConfiguration.java that allows attackers to impersonate any service that Jenkins connects to.
0
Attacker Value
Unknown

CVE-2017-14944

Disclosure Date: September 30, 2017 (last updated November 26, 2024)
Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060.
0