In Jenkins version 1.498 a medium severity vulnerability CVE-2017-1000362 was detected. This vulnerability allows attackers with local filesystem access to expose sensitive information because the re-key admin monitor created a world-readable backup directory containing all old secrets and their encryption key. These backups were not automatically removed. There’s no fix available for this issue at the moment. Additionally, administrators are advised to manually check and delete the $JENKINS_HOME/jenkins.security.RekeySecretAdminMonitor/backups directory if present. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-1000362.
Read more Developer ToolsIn GitLab EE versions 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 a low severity vulnerability CVE-2026-7471 was detected. This vulnerability allows an authenticated user with control of a virtual registry upstream to make unauthorized requests to internal hosts, potentially leading to Server-Side Request Forgery (SSRF). This occurs due to improper validation of the upstream requests. To address this issue, users should upgrade GitLab EE to versions 18.9.7, 18.10.6, or 18.11.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-7471.
Read more Developer ToolsIn Harbor versions through 1.3.0-rc4 a medium severity vulnerability CVE-2017-17697 was detected. This vulnerability allows an attacker to conduct Server-Side Request Forgery (SSRF) attacks via the endpoint parameter to the /api/targets/ping endpoint. This occurs due to a flaw in the Ping() function in the ui/api/target.go file. To address this issue, users should upgrade Harbor to version 1.3.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-17697.
Read more Developer ToolsIn GitLab CE/EE versions 8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 a medium severity vulnerability CVE-2026-8280 was detected. This vulnerability allows an authenticated user to cause a denial of service (DoS) through excessive memory consumption due to improper input validation. To address this issue, users should upgrade GitLab CE/EE to versions 18.9.7, 18.10.6, or 18.11.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-8280.
Read more Developer ToolsIn GitLab CE/EE versions 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 a medium severity vulnerability CVE-2026-8144 was detected. This vulnerability allows an authenticated user with project membership to enumerate private group members due to missing authorization checks. To address this issue, users should upgrade GitLab CE/EE to versions 18.9.7, 18.10.6, or 18.11.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-8144.
Read more Developer ToolsIn Jenkins versions through 2.93 a low severity vulnerability CVE-2017-17383 was detected. This vulnerability allows remote authenticated administrators to conduct Cross-Site Scripting (XSS) attacks by injecting a specially crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin. To address this issue, users should upgrade Jenkins to version 2.94. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-17383.
Read more Developer ToolsIn GitLab versions 9.4.x before 9.4.2 a medium severity vulnerability CVE-2017-17716 was detected. This vulnerability allows attackers to potentially intercept LDAP credentials or perform Man-in-the-Middle (MitM) attacks because the application does not support LDAP SSL certificate verification. This occurred because code related to the verify_certificates LDAP option was not merged. To address this issue, users should upgrade GitLab to version 9.4.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-17716.
Read more Developer ToolsIn Gogs versions 0.3.1-9 through 0.5.6.x before 0.5.6.1025 Beta a high severity vulnerability CVE-2014-8681 was detected. This vulnerability allows remote attackers to execute arbitrary SQL commands via the label parameter to user/repos/issues due to a SQL injection flaw in the GetIssues function in models/issue.go. To address this issue, users should upgrade Gogs to version 0.5.6.1025 Beta. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2014-8681.
Read more Developer ToolsIn GitLab Enterprise Edition (EE) versions 6.6.0 before 6.6.2 a medium severity vulnerability CVE-2014-3456 was detected. This vulnerability allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, leading to Cross-Site Scripting (XSS). To address this issue, users should upgrade GitLab Enterprise Edition (EE) to version 6.6.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2014-3456.
Read more Developer Tools