All CVEs — page 195 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This vulnerability allows authenticated users to inject TAB characters into the providerRootDirectory parameter, leading to remote code execution as the builds worker process user.
The flaw allows an attacker to inject arbitrary file paths and connection strings, leading to arbitrary file creation and overwrite, and potential credential theft.
The flaw allows an attacker to bypass authentication by setting a specific HTTP header, enabling unauthorized access to administrative functions.