Security
Headlines
HeadlinesLatestCVEs

Source

ghsa

GHSA-px3r-27qc-hx5g: NT auth module vulnerability in OpenAM

The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."

ghsa
#vulnerability#git#samba#auth
GHSA-35r9-gfqf-r6cw: Missing permission check in Jenkins vRealize Orchestrator Plugin

A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request to an attacker-specified URL.

GHSA-c965-p3w4-835c: Cross-Site Request Forgery in Jenkins vRealize Orchestrator Plugin

A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers to send an HTTP POST request to an attacker-specified URL.

GHSA-rq99-93c5-33f6: Cross-Site Request Forgery in Jenkins ThreadFix Plugin

A cross-site request forgery (CSRF) vulnerability in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers to connect to an attacker-specified URL.

GHSA-88r9-hfj2-54hv: Cross-site Scripting in Jenkins Stash Branch Parameter Plugin

Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier does not escape the name and description of Stash Branch parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

GHSA-vqpp-q5x5-qj4r: Cross-Site Request Forgery in Jenkins Beaker builder Plugin

A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to connect to an attacker-specified URL.

GHSA-rwqr-c348-m5wr: Denial of Service in aiohttp

aiohttp v3.8.1 was discovered to contain an invalid IPv6 URL which can lead to a Denial of Service (DoS).

GHSA-9pvq-4cc7-24jg: Cross-site Scripting in Jfinal CMS

Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.

GHSA-5ww9-9qp2-x524: Improper handling of double quotes in file name in Diffy in Windows environment

The function that calls the diff tool in versions of Diffy prior to 3.4.1 does not properly handle double quotes in a filename when run in a Windows environment. This allows attackers to execute arbitrary commands via a crafted string.

GHSA-w24x-87mr-4r23: SpEL Injection in Spring Data MongoDB

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.