Author: Angelo Barbosa

CVE-2023-49090 | CarrierWave up to 2.2.4/3.0.4 cross site scripting (GHSA-gxhx-g4fq-49hj)

A vulnerability, which was classified as problematic, has been found in CarrierWave up to 2.2.4/3.0.4. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. This vulnerability is handled as CVE-2023-49090. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2023-49652 | Google Compute Engine Plugin 4.550.vb_327fca_3db_11 on Jenkins permission

A vulnerability classified as problematic was found in Google Compute Engine Plugin 4.550.vb_327fca_3db_11 on Jenkins. Affected by this vulnerability is an unknown functionality. The manipulation leads to permission issues. This vulnerability is known as CVE-2023-49652. The attack can only be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More