|
268971
|
4.3 |
MEDIUM
Network
|
jenkins redhat
|
jenkins openshift
|
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information …
|
CWE-200
Information Exposure
|
CVE-2016-3727
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268972
|
7.4 |
HIGH
Network
|
jenkins redhat
|
jenkins openshift
|
Multiple open redirect vulnerabilities in Jenkins before 2.3 and LTS before 1.651.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vector…
|
NVD-CWE-Other
|
CVE-2016-3726
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268973
|
4.3 |
MEDIUM
Network
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of update site metadata by leveraging a missing permissions check. NOTE: this issue can be combined wit…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3725
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268974
|
6.5 |
MEDIUM
Network
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.
|
CWE-200
Information Exposure
|
CVE-2016-3724
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268975
|
4.3 |
MEDIUM
Network
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified…
|
CWE-200
Information Exposure
|
CVE-2016-3723
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268976
|
4.3 |
MEDIUM
Network
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the "full name."
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3722
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268977
|
6.5 |
MEDIUM
Network
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
|
CWE-17
Code
|
CVE-2016-3721
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268978
|
7.5 |
HIGH
Network
|
canonical xmlsoft debian hp opensuse
|
ubuntu_linux libxml2 debian_linux icewall_file_manager icewall_federation_agent leap
|
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to caus…
|
CWE-20
Improper Input Validation
|
CVE-2016-3705
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268979
|
7.5 |
HIGH
Network
|
fedoraproject debian xstream_project
|
fedora debian_linux xstream
|
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStre…
|
CWE-200
Information Exposure
|
CVE-2016-3674
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268980
|
7.5 |
HIGH
Network
|
opensuse debian hp xmlsoft canonical redhat oracle
|
leap debian_linux icewall_file_manager icewall_federation_agent libxml2 ubuntu_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enter…
|
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consum…
|
CWE-674
Uncontrolled Recursion
|
CVE-2016-3627
|
2024-11-21 11:50 |
2016-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|