Security
Headlines
HeadlinesLatestCVEs

Tag

#xss

CVE-2022-27198: Jenkins Security Advisory 2022-03-15

A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token.

CVE
#xss#csrf#vulnerability#mac#js#git#java#kubernetes
CVE-2022-0970: Added XSS check for uploaded SVG files before they get stored · getgrav/grav@f19297d

Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.

CVE-2022-27195: Jenkins Security Advisory 2022-03-15

Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files. These values are stored unencrypted and can be viewed by users with access to the Jenkins controller file system.

CVE-2022-27196: Jenkins Security Advisory 2022-03-15

Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure or Item/Create permissions.

CVE-2022-27197: Jenkins Security Advisory 2022-03-15

Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure views.

CVE-2022-27200: Jenkins Security Advisory 2022-03-15

Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the configuration form, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.

CVE-2022-0967: Upload file vulnerability · star7th/showdoc@3caa323

Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0963: Unrestricted XML Files Leads to Stored XSS in microweber

Unrestricted XML Files Leads to Stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0957: Stored XSS via File Upload in showdoc

Stored XSS via File Upload in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-0956: file upload bug · star7th/showdoc@56e450c

Stored XSS via File Upload in GitHub repository star7th/showdoc prior to v.2.10.4.