|
269631
|
- |
|
jenkins redhat
|
jenkins openshift
|
Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web s…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5326
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269632
|
- |
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: this vulnerability exists because of an incomplete…
|
CWE-284
Improper Access Control
|
CVE-2015-5325
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269633
|
- |
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5324
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269634
|
- |
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another u…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5323
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269635
|
- |
|
redhat jenkins
|
openshift jenkins
|
Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via direc…
|
CWE-22
Path Traversal
|
CVE-2015-5322
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269636
|
- |
|
redhat jenkins
|
openshift jenkins
|
The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to the page…
|
CWE-200
Information Exposure
|
CVE-2015-5321
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269637
|
- |
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive informatio…
|
CWE-200
Information Exposure
|
CVE-2015-5320
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269638
|
- |
|
redhat jenkins
|
openshift jenkins
|
XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to read arbitrary files via a crafted job configuration th…
|
NVD-CWE-Other
|
CVE-2015-5319
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269639
|
- |
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protection tokens, which makes it easier for remote attackers to bypass the CSRF protection mechanism via …
|
CWE-352
Origin Validation Error
|
CVE-2015-5318
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269640
|
- |
|
openstack
|
ironic_inspector
|
OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by trigge…
|
CWE-254
7PK - Security Features
|
CVE-2015-5306
|
2024-11-21 11:32 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|