LiveActive security incident?Get immediate response
CVE archive

July 2019

Browse CVE records published in July 2019, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1520 matching CVEs · Page 23 of 31.

Unknown · CVSS Not scored

CVE-2019-10341: A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestCon...

A missing permission check in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Published Jul 11, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-10352: A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/...

A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.

Published Jul 17, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-10340: A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.Descript...

A cross-site request forgery vulnerability in Jenkins Docker Plugin 1.1.6 and earlier in DockerAPI.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Published Jul 11, 2019 · Updated Aug 4, 2024

Medium · CVSS 6.5

CVE-2019-10198: An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7.

An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through the web UI or API, if they can discover or guess the UUID of the task.

Published Jul 31, 2019 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2019-10267: An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50.

An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to upload a file into any directory of the server. One can insert a JSP shell into the web server's directory and execute it. This leads to full access to the system, as the configured user (e.g., Administrator).

Published Jul 26, 2019 · Updated Aug 4, 2024

High · CVSS 7.2

CVE-2019-10192: A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before...

A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL encoding to write up to 3 bytes beyond the end of a heap-allocated buffer.

Published Jul 11, 2019 · Updated Aug 4, 2024

High · CVSS 7.2

CVE-2019-10193: A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before...

A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of up to 12 bytes past the end of a stack-allocated buffer.

Published Jul 11, 2019 · Updated Aug 4, 2024

High · CVSS 8.2

CVE-2019-10185: It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack durin...

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

Published Jul 31, 2019 · Updated Aug 4, 2024

High · CVSS 8.8

CVE-2019-10161: It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the...

It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the existence of arbitrary files, cause denial of service or cause libvirtd to execute arbitrary programs.

Published Jul 30, 2019 · Updated Aug 4, 2024

High · CVSS 8.1

CVE-2019-10137: A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processe...

A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the proxy's filesystem, or can execute arbitrary code in the context of the httpd process.

Published Jul 2, 2019 · Updated Aug 4, 2024

Low · CVSS 3.5

CVE-2019-10162: A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an a...

A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while looking up the NS/A/AAAA records it is about to use for an outgoing notify.

Published Jul 30, 2019 · Updated Aug 4, 2024

High · CVSS 7.3

CVE-2019-10173: It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deseriali...

It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)

Published Jul 23, 2019 · Updated Aug 4, 2024

High · CVSS 7.1

CVE-2019-10142: A flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x u...

A flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parameter passed to an ioctl was incorrectly validated and used in size calculations for the page size calculation. An attacker can use this flaw to crash the system, corrupt memory, or create other adverse security affects.

Published Jul 30, 2019 · Updated Aug 4, 2024

Medium · CVSS 5

CVE-2019-10153: A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest...

A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM is a member.

Published Jul 30, 2019 · Updated Aug 4, 2024

Low · CVSS 3.5

CVE-2019-10163: A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a rem...

A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue.

Published Jul 30, 2019 · Updated Aug 4, 2024

Low · CVSS 3.2

CVE-2019-10183: Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to c...

Virt-install(1) utility used to provision new virtual machines has introduced an option '--unattended' to create VMs without user interaction. This option accepts guest VM password as command line arguments, thus leaking them to others users on the system via process listing. It was introduced recently in the virt-manager v2.2.0 release.

Published Jul 3, 2019 · Updated Aug 4, 2024

Medium · CVSS 6.5

CVE-2019-10129: A vulnerability was found in postgresql versions 11.x prior to 11.3.

A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any user can create a partitioned table suitable for this attack. (Exploit prerequisites are the same as for CVE-2018-1052).

Published Jul 30, 2019 · Updated Aug 4, 2024

High · CVSS 7.5

CVE-2019-10152: A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles sym...

A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator tries to copy a file from/to the container.

Published Jul 30, 2019 · Updated Aug 4, 2024