πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-27208 β€Ό

Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read arbitrary files on the Jenkins controller.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27204 β€Ό

A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers to connect to an attacker-specified URL.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27197 β€Ό

Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure views.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27199 β€Ό

A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers with Overall/Read permission to connect to an AWS service using an attacker-specified token.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27212 β€Ό

Jenkins List Git Branches Parameter Plugin 0.0.9 and earlier does not escape the name of the 'List Git branches (and more)' parameter, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27213 β€Ό

Jenkins Environment Dashboard Plugin 1.1.10 and earlier does not escape the Environment order and the Component order configuration values in its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0964 β€Ό

Stored XSS viva .webmv file upload in GitHub repository star7th/showdoc prior to 2.10.4.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26779 β€Ό

Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that the invite is sent, could generate time deterministic tokens and brute force attempt to use them prior to the legitimate receiver accepting the invite. This feature is not enabled by default, the attacker is required to know or guess the project ID for the invite in addition to the invitation token, and the attacker would need to be an existing authorized user of CloudStack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27200 β€Ό

Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the configuration form, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-27218 β€Ό

Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Praetorian Launches Chariot Total Attack Life Cycle Solution πŸ•΄

New platform combines AI-based attack surface management automation with offensive security managed services to identify exposures and prioritize risk management.

πŸ“– Read

via "Dark Reading".
πŸ•΄ OneLayer Secures $8.2M Seed Round to Protect Private 5G Networks πŸ•΄

OneLayer plans to use the funds to build its product suite.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Incognia Introduces New Location Identity Fraud Detection Tools πŸ•΄

Modules include Location Spoofing Detection, Global Mobile Address Validation, and Trusted Device Intelligence.

πŸ“– Read

via "Dark Reading".
πŸ” Utah Set to Pass U.S.'s Next Data Privacy Bill πŸ”

Utah looks like it will become the fourth U.S. state, after California, Virginia, and Colorado, to pass comprehensive consumer privacy legislation.

πŸ“– Read

via "".
❌ Cyberattacks Against Israeli Government Sites: β€˜Largest in the Country’s History’ ❌

DDoS attacks against Israel telecom companies took down government sites, sparking a temporary state of emergency.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2022-25488 β€Ό

Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25497 β€Ό

CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45848 β€Ό

Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to crash Nicotine+ by sending a file download request with a file path containing a null character.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25494 β€Ό

Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25485 β€Ό

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25486 β€Ό

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.

πŸ“– Read

via "National Vulnerability Database".