|
257271
|
7.5 |
HIGH
Network
|
mercurial debian redhat
|
mercurial debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_serv…
|
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
|
CWE-59
Link Following
|
CVE-2017-1000115
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257272
|
3.1 |
LOW
Network
|
jenkins
|
datadog
|
The Datadog Plugin stores an API key to access the Datadog service in the global Jenkins configuration. While the API key is stored encrypted on disk, it was transmitted in plain text as part of the …
|
CWE-200
Information Exposure
|
CVE-2017-1000114
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257273
|
5.5 |
MEDIUM
Local
|
jenkins
|
deploy
|
The Deploy to container Plugin stored passwords unencrypted as part of its configuration. This allowed users with Jenkins master local file system access, or users with Extended Read access to the jo…
|
CWE-200
Information Exposure
|
CVE-2017-1000113
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257274
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data() calls ip_ufo_append_data() to append. However in between two…
|
CWE-362
Race Condition
|
CVE-2017-1000112
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257275
|
7.8 |
HIGH
Local
|
linux redhat debian
|
linux_kernel enterprise_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_lin…
|
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-1000111
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257276
|
4.3 |
MEDIUM
Network
|
jenkins
|
blue_ocean
|
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines …
|
CWE-287
Improper Authentication
|
CVE-2017-1000110
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257277
|
6.1 |
MEDIUM
Network
|
jenkins
|
owasp_dependency-check
|
The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the i…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000109
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257278
|
7.5 |
HIGH
Network
|
jenkins
|
pipeline-input-step
|
The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item…
|
CWE-200
Information Exposure
|
CVE-2017-1000108
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257279
|
8.8 |
HIGH
Network
|
jenkins
|
script_security
|
Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions.…
|
NVD-CWE-noinfo
|
CVE-2017-1000107
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257280
|
5.3 |
MEDIUM
Network
|
jenkins
|
blue_ocean
|
The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission wa…
|
CWE-862
Missing Authorization
|
CVE-2017-1000105
|
2024-11-21 12:04 |
2017-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|