Author: Angelo Barbosa

CVE-2023-49296 | Arduino Create Agent up to 1.3.5 Web Interface /certificate.crt cross site scripting (GHSA-j5hc-wx84-844h)

A vulnerability, which was classified as problematic, has been found in Arduino Create Agent up to 1.3.5. This issue affects some unknown processing of the file /certificate.crt of the component Web Interface. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2023-49296. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-50777 | PaaSLane Estimate Plugin up to 1.0.4 on Jenkins Job Configuration Form information disclosure

A vulnerability classified as problematic was found in PaaSLane Estimate Plugin up to 1.0.4 on Jenkins. This vulnerability affects unknown code of the component Job Configuration Form Handler. The manipulation leads to information disclosure. This vulnerability was named CVE-2023-50777. Access to the local network is required for this attack to succeed. There is no exploit...

Read More

CVE-2023-50776 | PaaSLane Estimate Plugin up to 1.0.4 on Jenkins Controller File System information disclosure

A vulnerability classified as problematic has been found in PaaSLane Estimate Plugin up to 1.0.4 on Jenkins. This affects an unknown part of the component Controller File System Handler. The manipulation leads to information disclosure. This vulnerability is uniquely identified as CVE-2023-50776. Access to the local network is required for this attack. There is no exploit...

Read More

CVE-2023-50773 | Dingding JSON Pusher Plugin up to 2.0 on Jenkins Job Configuration Form information disclosure

A vulnerability was found in Dingding JSON Pusher Plugin up to 2.0 on Jenkins. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Job Configuration Form Handler. The manipulation leads to information disclosure. This vulnerability is handled as CVE-2023-50773. The attack needs to be initiated within the local network. There is no exploit...

Read More