πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2022-39301 β€Ό

sra-admin is a background rights management system that separates the front and back end. sra-admin version 1.1.1 has a storage cross-site scripting (XSS) vulnerability. After logging into the sra-admin background, an attacker can upload an html page containing xss attack code in "Personal Center" - "Profile Picture Upload" allowing theft of the user's personal information. This issue has been patched in 1.1.2. There are no known workarounds.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Kaspersky Launches New VPN to Amplify Speed and Convenience πŸ•΄

New version boosts VPN tunnel performance and lets users prioritize secure connection traffic for certain services.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Zscaler Advances Enterprise Data Security With Zero-Configuration Data Protection πŸ•΄

New data-protection innovations mitigate security risks by expediting deployment cycles and simplifying operational complexity.

πŸ“– Read

via "Dark Reading".
⚠ Women in Cryptology – USPS celebrates WW2 codebreakers ⚠

What did you do in the war, Mom? Oh, y'know, a bit of this and that...

πŸ“– Read

via "Naked Security".
πŸ‘1
πŸ•΄ SBOMs: An Overhyped Concept That Won't Secure Your Software Supply Chain πŸ•΄

We need more than the incomplete snapshot SBOMs provide to have real impact.

πŸ“– Read

via "Dark Reading".
πŸ‘1
β€Ό CVE-2022-43428 β€Ό

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43433 β€Ό

Jenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43409 β€Ό

Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43419 β€Ό

Jenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43420 β€Ό

Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control or modify Contrast service API responses.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43434 β€Ό

Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43435 β€Ό

Jenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43426 β€Ό

Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potential for attackers to observe and capture it.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43430 β€Ό

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43408 β€Ό

Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to generate URLs to proceed or abort Pipeline builds, allowing attackers able to configure Pipelines to specify 'input' step IDs resulting in URLs that would bypass the CSRF protection of any target URL in Jenkins.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43418 β€Ό

A cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43422 β€Ό

Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43427 β€Ό

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43414 β€Ό

Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specified directory as test results, allowing attackers able to control agent processes to obtain test results from files in an attacker-specified directory on the Jenkins controller.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43413 β€Ό

Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43407 β€Ό

Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specified ID of the 'input' step, which is used for the URLs that process user interactions for the given 'input' step (proceed or abort) and is not correctly encoded, allowing attackers able to configure Pipelines to have Jenkins build URLs from 'input' step IDs that would bypass the CSRF protection of any target URL in Jenkins when the 'input' step is interacted with.

πŸ“– Read

via "National Vulnerability Database".