• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2022-38663
2022-08-25
N/A
6.5 MEDIUM
Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePassword`) credentials binding.
CVE-2022-38662
2022-12-23
N/A
6.1 MEDIUM
In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.
CVE-2022-38661
2022-12-14
N/A
7.1 HIGH
HCL Workload Automation could allow a local user to overwrite key system files which would cause the system to crash.
CVE-2022-38660
2022-11-07
N/A
8.8 HIGH
HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in the application on behalf of the logged in user.
CVE-2022-3866
Hashicorp, Nomad
Boundary, Consul, Consul_docker_image, Consul_template, Go-getter, Go-slug, Nomad, Packer, Sentinel, Terraform
2022-11-15
N/A
4.3 MEDIUM
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.
CVE-2022-38659
2022-12-23
N/A
7.8 HIGH
In specific scenarios, on Windows the operator credentials may be encrypted in a manner that is not completely machine-dependent.
CVE-2022-38658
2022-12-30
N/A
7.5 HIGH
BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data exposed.
CVE-2022-38657
2023-02-21
N/A
5.4 MEDIUM
An open redirect to malicious sites can occur when accessing the "Feedback" action on the manager page.
CVE-2022-38656
2022-12-14
N/A
9.8 CRITICAL
HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.
CVE-2022-38655
2022-12-28
N/A
5.8 MEDIUM
BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixlets or to deploy fixlets from the BES Support external site.
« Previous 1 … 9,442 9,443 9,444 9,445 9,446 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE