CVE-2022-2648
published 2022-08-04CVE-2022-2648: A vulnerability was found in SourceCodester Multi Language Hotel Management Software. It has been rated as critical. This issue affects some unknown…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.72%
49.7th percentile
A vulnerability was found in SourceCodester Multi Language Hotel Management Software. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument room_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205595.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sourcecodester | multi_language_hotel_management_software | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c72w-cxrv-87g2: A vulnerability was found in SourceCodester Multi Language Hotel Management Software
ghsa_unreviewed·2022-08-05
CVE-2022-2648 [CRITICAL] CWE-89 GHSA-c72w-cxrv-87g2: A vulnerability was found in SourceCodester Multi Language Hotel Management Software
A vulnerability was found in SourceCodester Multi Language Hotel Management Software. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument room_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205595.
GHSA
Jenkins Pipeline: Groovy Plugin has Insufficiently Protected Credentials
ghsa·2022-02-16
CVE-2022-25180 [MEDIUM] CWE-319 Jenkins Pipeline: Groovy Plugin has Insufficiently Protected Credentials
Jenkins Pipeline: Groovy Plugin has Insufficiently Protected Credentials
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds.
This allows attackers with Run/Replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.
Pipeline: Groovy Plugin 2656.vf7a_e7b_75a_457 does not allow builds containing password parameters to be replayed.
GHSA
Improper Link Resolution Before File Access in Jenkins Pipeline: Groovy Plugin
ghsa·2022-02-16
CVE-2022-25176 [MEDIUM] CWE-59 Improper Link Resolution Before File Access in Jenkins Pipeline: Groovy Plugin
Improper Link Resolution Before File Access in Jenkins Pipeline: Groovy Plugin
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers able to configure Pipelines to read arbitrary files on the Jenkins controller file system.
Red Hat
workflow-cps: Password parameters are included from the original build in replayed builds
vendor_redhat·2022-02-15·CVSS 4.3
CVE-2022-25180 [MEDIUM] CWE-522 workflow-cps: Password parameters are included from the original build in replayed builds
workflow-cps: Password parameters are included from the original build in replayed builds
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in replayed builds, allowing attackers with Run/Replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.
A flaw was found in Jenkins. The Pipeline: Groovy Plugin includes password parameters from the original build in replayed builds. This flaw allows attackers with run/replay permission to obtain the values of password parameters passed to previous builds of a Pipeline.
Red Hat
workflow-cps: OS command execution through crafted SCM contents
vendor_redhat·2022-02-15·CVSS 8.8
CVE-2022-25173 [HIGH] CWE-78 workflow-cps: OS command execution through crafted SCM contents
workflow-cps: OS command execution through crafted SCM contents
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
A flaw was found in Jenkins. The Pipeline: Groovy Plugin uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines. This flaw allows attackers with item/configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
Red Hat
workflow-cps: Pipeline-related plugins follow symbolic links or do not limit path names
vendor_redhat·2022-02-15·CVSS 6.5
CVE-2022-25176 [MEDIUM] CWE-59 workflow-cps: Pipeline-related plugins follow symbolic links or do not limit path names
workflow-cps: Pipeline-related plugins follow symbolic links or do not limit path names
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checkout directory for the configured SCM when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers able to configure Pipelines to read arbitrary files on the Jenkins controller file system.
A flaw was found in Jenkins. The Pipeline: Groovy Plugin follows symbolic links to locations outside of the checkout directory for the configured SCM when reading the script file (typically Jenkinsfile) for Pipelines. This flaw allows attackers who can configure Pipelines to read arbitrary files on the Jenkins controller file system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-04
Published