Autore: Angelo Barbosa

CVE-2023-50770 | OpenId Connect Authentication Plugin up to 2.6 on Jenkins Controller File System information disclosure

A vulnerability was found in OpenId Connect Authentication Plugin up to 2.6 on Jenkins. It has been declared as problematic. This vulnerability affects unknown code of the component Controller File System Handler. The manipulation leads to information disclosure. This vulnerability was named CVE-2023-50770. An attack has to be approached locally. There is no exploit...

Per saperne di più

CVE-2023-48702 | Jellyfin up to 10.8.12 Path ProcessStartInfo command injection (GHSA-rr9h-w522-cvmr)

A vulnerability was found in Jellyfin up to 10.8.12 and classified as critical. Affected by this issue is the function ProcessStartInfo of the file /System/MediaEncoder/Path. The manipulation leads to command injection. This vulnerability is handled as CVE-2023-48702. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più