NA - CVE-2024-33210 - A cross-site scripting (XSS) vulnerability has...
A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users.
NA - CVE-2024-47803 - Jenkins 2.478 and earlier, LTS 2.462.2 and...
Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form field.
NA - CVE-2024-47804 - If an attempt is made to create an item of a...
If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either...
NA - CVE-2024-47805 - Jenkins Credentials Plugin 1380.va_435002fa_924...
Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item...
NA - CVE-2024-47806 - Jenkins OpenId Connect Authentication Plugin...
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow,...
NA - CVE-2024-47807 - Jenkins OpenId Connect Authentication Plugin...
Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow,...
NA - CVE-2024-6360 - Incorrect Permission Assignment for Critical...
Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica agent apikey. This...
NA - CVE-2024-9423 - Certain HP LaserJet printers may potentially...
Certain HP LaserJet printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer. The printer displays a “JPEG Unsupported” message which may not clear,...
NA - CVE-2024-20365 - A vulnerability in the Redfish API of Cisco UCS...
A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers could allow an authenticated, remote attacker with administrative privileges to...
NA - CVE-2024-20385 - A vulnerability in the SSL/TLS implementation...
A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an unauthenticated, remote attacker to intercept sensitive information from an affected...