|
269461
|
- |
|
redhat
|
automatic_bug_reporting_tool enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node
|
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users to write to arbitrary files via a symlink attack on unpacked.cpio i…
|
CWE-59
Link Following
|
CVE-2015-5273
|
2024-11-21 11:32 |
2015-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269462
|
- |
|
redhat
|
ceph
|
CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks…
|
NVD-CWE-Other
|
CVE-2015-5245
|
2024-11-21 11:32 |
2015-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269463
|
- |
|
jenkins redhat
|
jenkins openshift
|
Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web s…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5326
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269464
|
- |
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: this vulnerability exists because of an incomplete…
|
CWE-284
Improper Access Control
|
CVE-2015-5325
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269465
|
- |
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5324
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269466
|
- |
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another u…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5323
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269467
|
- |
|
redhat jenkins
|
openshift jenkins
|
Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via direc…
|
CWE-22
Path Traversal
|
CVE-2015-5322
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269468
|
- |
|
redhat jenkins
|
openshift jenkins
|
The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to the page…
|
CWE-200
Information Exposure
|
CVE-2015-5321
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269469
|
- |
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive informatio…
|
CWE-200
Information Exposure
|
CVE-2015-5320
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269470
|
- |
|
redhat jenkins
|
openshift jenkins
|
XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to read arbitrary files via a crafted job configuration th…
|
NVD-CWE-Other
|
CVE-2015-5319
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|