|
199441
|
6.1 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
A cross-site scripting (XSS) vulnerability exists when visiting malicious websites with the Palo Alto Networks GlobalProtect Clientless VPN that can compromise the user's active session. This issue a…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2005
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199442
|
5.5 |
MEDIUM
Local
|
paloaltonetworks
|
globalprotect
|
Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshooting on GlobalProtect app (also known as GlobalProtec…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-2004
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199443
|
6.5 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system files affecting the integrity of the system or causi…
|
NVD-CWE-Other
|
CVE-2020-2003
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199444
|
9.8 |
CRITICAL
Network
|
paloaltonetworks
|
pan-os
|
An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated user with network access to PAN-OS management interfa…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-2001
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199445
|
8.1 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
An authentication bypass by spoofing vulnerability exists in the authentication daemon and User-ID components of Palo Alto Networks PAN-OS by failing to verify the integrity of the Kerberos key distr…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-2002
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199446
|
8.8 |
HIGH
Network
|
jenkins
|
source_code_management_filter_jervis
|
Jenkins SCM Filter Jervis Plugin 0.2.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-2189
|
2024-11-21 14:24 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199447
|
4.3 |
MEDIUM
Network
|
jenkins
|
amazon_ec2
|
A missing permission check in Jenkins Amazon EC2 Plugin 1.50.1 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.
|
CWE-863
Incorrect Authorization
|
CVE-2020-2188
|
2024-11-21 14:24 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199448
|
5.6 |
MEDIUM
Network
|
jenkins
|
amazon_ec2
|
Jenkins Amazon EC2 Plugin 1.50.1 and earlier unconditionally accepts self-signed certificates and does not perform hostname validation, enabling man-in-the-middle attacks.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-2187
|
2024-11-21 14:24 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199449
|
4.3 |
MEDIUM
Network
|
jenkins
|
amazon_ec2
|
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.50.1 and earlier allows attackers to provision instances.
|
CWE-352
Origin Validation Error
|
CVE-2020-2186
|
2024-11-21 14:24 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199450
|
5.6 |
MEDIUM
Network
|
jenkins
|
amazon_ec2
|
Jenkins Amazon EC2 Plugin 1.50.1 and earlier does not validate SSH host keys when connecting agents, enabling man-in-the-middle attacks.
|
NVD-CWE-Other
|
CVE-2020-2185
|
2024-11-21 14:24 |
2020-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|