|
257711
|
7.8 |
HIGH
Local
|
linux redhat debian
|
linux_kernel enterprise_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_lin…
|
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-1000111
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257712
|
4.3 |
MEDIUM
Network
|
jenkins
|
blue_ocean
|
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines …
|
CWE-287
Improper Authentication
|
CVE-2017-1000110
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257713
|
6.1 |
MEDIUM
Network
|
jenkins
|
owasp_dependency-check
|
The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the i…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000109
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257714
|
7.5 |
HIGH
Network
|
jenkins
|
pipeline-input-step
|
The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item…
|
CWE-200
Information Exposure
|
CVE-2017-1000108
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257715
|
8.8 |
HIGH
Network
|
jenkins
|
script_security
|
Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions.…
|
NVD-CWE-noinfo
|
CVE-2017-1000107
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257716
|
5.3 |
MEDIUM
Network
|
jenkins
|
blue_ocean
|
The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission wa…
|
CWE-862
Missing Authorization
|
CVE-2017-1000105
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257717
|
5.4 |
MEDIUM
Network
|
jenkins
|
dry
|
The custom Details view of the Static Analysis Utilities based DRY Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000103
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257718
|
5.4 |
MEDIUM
Network
|
jenkins
|
static_analysis_utilities
|
The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to these plugins, for e…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000102
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257719
|
8.5 |
HIGH
Network
|
jenkins
|
blue_ocean
|
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines …
|
CWE-287
Improper Authentication
|
CVE-2017-1000106
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257720
|
6.5 |
MEDIUM
Network
|
jenkins
|
config_file_provider
|
The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs …
|
CWE-269
Improper Privilege Management
|
CVE-2017-1000104
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|