CVE-2019-2602
- EPSS 0.22%
- Veröffentlicht 23.04.2019 19:32:50
- Zuletzt bearbeitet 21.11.2024 04:41:11
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unau...
CVE-2019-3899
- EPSS 0.4%
- Veröffentlicht 22.04.2019 16:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:49
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.
- EPSS 0.1%
- Veröffentlicht 22.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 04:20:47
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a differe...
CVE-2019-1003049
- EPSS 0.42%
- Veröffentlicht 10.04.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:17:48
Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these ...
CVE-2019-1003050
- EPSS 0.99%
- Veröffentlicht 10.04.2019 21:29:01
- Zuletzt bearbeitet 21.11.2024 04:17:48
The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to c...
CVE-2019-0211
- EPSS 88.57%
- Veröffentlicht 08.04.2019 22:29:00
- Zuletzt bearbeitet 27.10.2025 17:37:51
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with...
CVE-2019-3876
- EPSS 0.2%
- Veröffentlicht 01.04.2019 15:29:01
- Zuletzt bearbeitet 21.11.2024 04:42:46
A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via Jav...
CVE-2019-1002100
- EPSS 11.12%
- Veröffentlicht 01.04.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:17:42
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Ty...
CVE-2019-1002101
- EPSS 48.75%
- Veröffentlicht 01.04.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:17:42
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar b...
CVE-2019-1003040
- EPSS 2.25%
- Veröffentlicht 28.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:17:47
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.