|
248461
|
6.5 |
MEDIUM
Network
|
jenkins
|
email_extension
|
An exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/emailext/ExtendedEmailPublisher/global.groovy and Exten…
|
CWE-200
Information Exposure
|
CVE-2018-1000176
|
2024-11-21 12:39 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248462
|
6.5 |
MEDIUM
Network
|
jenkins
|
html_publisher
|
A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arb…
|
CWE-22
Path Traversal
|
CVE-2018-1000175
|
2024-11-21 12:39 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248463
|
6.1 |
MEDIUM
Network
|
jenkins
|
google_login
|
An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login.
|
CWE-601
Open Redirect
|
CVE-2018-1000174
|
2024-11-21 12:39 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248464
|
5.9 |
MEDIUM
Network
|
jenkins
|
google_login
|
A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another user if they can cont…
|
CWE-384
Session Fixation
|
CVE-2018-1000173
|
2024-11-21 12:39 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248465
|
7.5 |
HIGH
Network
|
nghttp2 nodejs debian
|
nghttp2 node.js debian_linux
|
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service…
|
CWE-20 CWE-476
Improper Input Validation NULL Pointer Dereference
|
CVE-2018-1000168
|
2024-11-21 12:39 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248466
|
4.8 |
MEDIUM
Network
|
imagely
|
nextgen_gallery
|
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image …
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000172
|
2024-11-21 12:39 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248467
|
7.5 |
HIGH
Network
|
lightsaml
|
lightsaml
|
LightSAML version prior to 1.3.5 contains a Incorrect Access Control vulnerability in signature validation in readers in src/LightSaml/Model/XmlDSig/ that can result in impersonation of any user from…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-1000165
|
2024-11-21 12:39 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248468
|
7.5 |
HIGH
Network
|
gunicorn debian
|
gunicorn debian_linux
|
gunicorn version 19.4.5 contains a CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers vulnerability in "process_headers" function in "gunicorn/http/wsgi.py" that can result in an atta…
|
CWE-93
CRLF Injection
|
CVE-2018-1000164
|
2024-11-21 12:39 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248469
|
6.1 |
MEDIUM
Network
|
projectfloodlight
|
floodlight
|
Floodlight version 1.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in the web console that can result in javascript injections into the web page. This attack appears to be exploit…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000163
|
2024-11-21 12:39 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248470
|
6.1 |
MEDIUM
Network
|
parsedown
|
parsedown
|
Parsedown version prior to 1.7.0 contains a Cross Site Scripting (XSS) vulnerability in `setMarkupEscaped` for escaping HTML that can result in JavaScript code execution. This attack appears to be ex…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000162
|
2024-11-21 12:39 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|