FreshPorts - VuXML
This page displays vulnerability information about FreeBSD Ports.
The last vuln.xml file processed by FreshPorts is:
Revision: 318751
Date: 2013-05-22
Time: 09:14:17Z
Committer: rene
List all Vulnerabilities, by package
List all Vulnerabilities, by date
These are the vulnerabilities relating to the commit you have selected:
| VuXML ID | Description |
| 3a65d33b-5950-11e2-b66b-00e0814cab4e | jenkins -- HTTP access to the server to retrieve the master cryptographic key
Jenkins Security Advisory reports:
This advisory announces a security vulnerability that was found
in Jenkins core.
An attacker can then use this master cryptographic key to mount
remote code execution attack against the Jenkins master, or
impersonate arbitrary users in making REST API calls.
There are several factors that mitigate some of these problems
that may apply to specific installations.
- The particular attack vector is only applicable on Jenkins
instances that have slaves attached to them, and allow
anonymous read access.
- Jenkins allows users to re-generate the API tokens. Those
re-generated API tokens cannot be impersonated by the
attacker.
Discovery 2013-01-04 Entry 2013-01-08 jenkins
lt 1.498
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-01-04
|