CVE-2018-1000862
- EPSS 0.18%
- Veröffentlicht 10.12.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:31
An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyon...
CVE-2018-1000863
- EPSS 7.56%
- Veröffentlicht 10.12.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:31
A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, poten...
CVE-2018-1000864
- EPSS 0.22%
- Veröffentlicht 10.12.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:31
A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
CVE-2018-1000865
- EPSS 0.62%
- Veröffentlicht 10.12.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:31
A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java that allows attackers with Job/Configure permission to execute arbitrary code on the J...
CVE-2018-1000866
- EPSS 0.62%
- Veröffentlicht 10.12.2018 14:29:01
- Zuletzt bearbeitet 21.11.2024 03:40:31
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java tha...
CVE-2018-18311
- EPSS 3.84%
- Veröffentlicht 07.12.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:40
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
CVE-2018-1002105
- EPSS 89.86%
- Veröffentlicht 05.12.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:40:38
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server...
CVE-2018-19475
- EPSS 63.59%
- Veröffentlicht 23.11.2018 05:29:03
- Zuletzt bearbeitet 21.11.2024 03:57:59
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
CVE-2018-19476
- EPSS 0.82%
- Veröffentlicht 23.11.2018 05:29:03
- Zuletzt bearbeitet 21.11.2024 03:57:59
psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion.
CVE-2018-19477
- EPSS 0.82%
- Veröffentlicht 23.11.2018 05:29:03
- Zuletzt bearbeitet 21.11.2024 03:57:59
psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion.