|
199591
|
6.5 |
MEDIUM
Network
|
jenkins
|
self-organizing_swarm_modules
|
A cross-site request forgery vulnerability in Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier allows attackers to add or remove agent labels.
|
CWE-352
Origin Validation Error
|
CVE-2020-2192
|
2024-11-21 14:24 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199592
|
4.3 |
MEDIUM
Network
|
jenkins
|
self-organizing_swarm_modules
|
Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier does not check permissions on API endpoints that allow adding and removing agent labels.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-2191
|
2024-11-21 14:24 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199593
|
5.4 |
MEDIUM
Network
|
jenkins
|
script_security
|
Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the In-process Script Approval page, resulting in a stored cross-site scripting vuln…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2190
|
2024-11-21 14:24 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199594
|
8.8 |
HIGH
Local
|
katacontainers
|
runtime
|
Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all sub…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-2025
|
2024-11-21 14:24 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199595
|
6.5 |
MEDIUM
Local
|
katacontainers
|
runtime
|
An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on th…
|
CWE-59
Link Following
|
CVE-2020-2024
|
2024-11-21 14:24 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199596
|
9.0 |
CRITICAL
Network
|
paloaltonetworks
|
pan-os
|
An authentication bypass vulnerability in the Panorama context switching feature allows an attacker with network access to a Panorama's management interface to gain privileged access to managed firew…
|
CWE-287
Improper Authentication
|
CVE-2020-2018
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199597
|
6.1 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces. A remote attacker able to convince an authenticated administrator to click on a crafted link to…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2017
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199598
|
7.0 |
HIGH
Local
|
paloaltonetworks
|
pan-os
|
A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker wh…
|
CWE-362
Race Condition
|
CVE-2020-2016
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199599
|
8.8 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
A buffer overflow vulnerability in the PAN-OS management server allows authenticated users to crash system processes or potentially execute arbitrary code with root privileges. This issue affects: PA…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-2015
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199600
|
8.8 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root privileges. This issue affects: All versions of P…
|
CWE-78
OS Command
|
CVE-2020-2014
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|