8.1

CVSS3.1

CVE-2024-47807 -

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.

📅 Published: Oct. 2, 2024, 3:35 p.m. 🔄 Last Modified: May 6, 2025, 9:13 p.m.

8.1

CVSS3.1

CVE-2024-47806 -

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication flow, potentially gaining administrator access to Jenkins.

📅 Published: Oct. 2, 2024, 3:35 p.m. 🔄 Last Modified: May 6, 2025, 9:14 p.m.

7.5

CVSS3.1

CVE-2024-47805 -

Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST API or CLI.

📅 Published: Oct. 2, 2024, 3:35 p.m. 🔄 Last Modified: March 14, 2025, 3:15 p.m.

4.3

CVSS3.1

CVE-2024-47804 - jenkins: Item creation restriction bypass vulnerability

If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API and either of these checks fail, Jenkins 2.478 and earlier, LTS 2.462.2 and earlier creates the item in memory, on…

📅 Published: Oct. 2, 2024, 3:35 p.m. 🔄 Last Modified: March 14, 2025, 4:15 p.m.

4.3

CVSS3.1

CVE-2024-47803 - jenkins: Exposure of multi-line secrets through error messages

Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form field.

📅 Published: Oct. 2, 2024, 3:35 p.m. 🔄 Last Modified: March 19, 2025, 6:15 p.m.

5.3

CVSS3.1

CVE-2024-9423 - Certain HP LaserJet Printers – Potential Denial of Service

Certain HP LaserJet printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer. The printer displays a “JPEG Unsupported” message which may not clear, potentially blocking queued print jobs.

📅 Published: Oct. 2, 2024, 3:21 p.m. 🔄 Last Modified: Feb. 24, 2026, 2:38 p.m.

6.9

CVSS4.0

CVE-2024-6360 - Incorrect Permission Assignment for Critical Resource vulnerability has been discovered in OpenText…

Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica agent apikey. This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0…

📅 Published: Oct. 2, 2024, 3:19 p.m. 🔄 Last Modified: Nov. 19, 2025, 1:30 p.m.

8.4

CVSS3.1

CVE-2024-44193 -

A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to elevate their privileges.

📅 Published: Oct. 2, 2024, 2:24 p.m. 🔄 Last Modified: April 2, 2026, 7:18 p.m.

3.5

CVSS3.1

CVE-2024-47612 - XSS in Special:DataDump when displaying dump status

DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-failed)). If these messages are edited (which r…

📅 Published: Oct. 2, 2024, 2:22 p.m. 🔄 Last Modified: July 12, 2025, 10:44 p.m.

6.3

CVSS4.0

CVE-2024-47611 - XZ Utils on Microsoft Windows platform are vulnerable to argument injection

XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command line tools from XZ Utils 5.6.2 and older have a command line argument injection vulnerability. If a command line contains Unicode characters (for examp…

📅 Published: Oct. 2, 2024, 2:16 p.m. 🔄 Last Modified: Nov. 21, 2024, 5:15 p.m.
Total resulsts: 342251
Page 7725 of 34,226
« previous page » next page
Filters