|
223411
|
6.5 |
MEDIUM
Network
|
jenkins
|
build_failure_analyzer
|
A user-supplied regular expression in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier was processed in a way that wasn't interruptible, allowing attackers to have Jenkins evaluate a regular …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2019-16555
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223412
|
4.3 |
MEDIUM
Network
|
jenkins
|
build_failure_analyzer
|
A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Read permission to have Jenkins evaluate a computationally expensive regular expre…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16554
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223413
|
8.8 |
HIGH
Network
|
jenkins
|
build_failure_analyzer
|
A cross-site request forgery vulnerability in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers to have Jenkins evaluate a computationally expensive regular expression.
|
CWE-352
Origin Validation Error
|
CVE-2019-16553
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223414
|
5.4 |
MEDIUM
Network
|
jenkins
|
gerrit_trigger
|
A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL or SSH server using attacker-…
|
CWE-276
Incorrect Default Permissions
|
CVE-2019-16552
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223415
|
8.8 |
HIGH
Network
|
jenkins
|
gerrit_trigger
|
A cross-site request forgery vulnerability in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers to connect to an attacker-specified HTTP URL or SSH server using attacker-specified cre…
|
CWE-352
Origin Validation Error
|
CVE-2019-16551
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223416
|
8.8 |
HIGH
Network
|
jenkins
|
maven
|
A cross-site request forgery vulnerability in a connection test form method in Jenkins Maven Release Plugin 0.16.1 and earlier allows attackers to have Jenkins connect to an attacker specified web se…
|
CWE-352
Origin Validation Error
|
CVE-2019-16550
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223417
|
8.1 |
HIGH
Network
|
jenkins
|
maven
|
Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-middle attackers to have Jenkins parse crafted XML …
|
CWE-611
XXE
|
CVE-2019-16549
|
2024-11-21 13:30 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223418
|
9.8 |
CRITICAL
Network
|
intesync
|
solismed
|
Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.
|
CWE-22
Path Traversal
|
CVE-2019-16246
|
2024-11-21 13:30 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223419
|
9.8 |
CRITICAL
Network
|
weidmueller
|
ie-sw-pl09m-5gc-4gt_firmware ie-sw-pl09mt-5gc-4gt_firmware ie-sw-pl18m-2gc-16tx_firmware ie-sw-pl18mt-2gc-16tx_firmware ie-sw-pl18m-2gc14tx2sc_firmware ie-sw-pl18mt-2gc14tx2sc_firmware…
|
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Authentication Information used in a cookie …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-16674
|
2024-11-21 13:30 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223420
|
6.5 |
MEDIUM
Network
|
weidmueller
|
ie-sw-pl09m-5gc-4gt_firmware ie-sw-pl09mt-5gc-4gt_firmware ie-sw-pl18m-2gc-16tx_firmware ie-sw-pl18mt-2gc-16tx_firmware ie-sw-pl18m-2gc14tx2sc_firmware ie-sw-pl18mt-2gc14tx2sc_firmware…
|
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Passwords are stored in cleartext and can be…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-16673
|
2024-11-21 13:30 |
2019-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|