Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
oauth vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-30528
Jenkins WSO2 Oauth Plugin 1.0 and previous versions does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for malicious users to observe and capture it.
Jenkins Wso2 Oauth
NA
CVE-2022-4148
The WP OAuth Server (OAuth Authentication) WordPress plugin prior to 4.3.0 has a flawed CSRF and authorisation check when deleting a client, which could allow any authenticated users, such as subscriber to delete arbitrary client.
Dash10 Oauth Server
2.1
CVSSv2
CVE-2019-10460
Jenkins Bitbucket OAuth Plugin 0.9 and previous versions stored credentials unencrypted in the global config.xml configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Jenkins Bitbucket Oauth
NA
CVE-2023-45144
com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and ...
Xwiki Oauth Identity
NA
CVE-2022-3632
The OAuth Client by DigitialPixies WordPress plugin up to and including 1.1.0 does not have CSRF checks in some places, which could allow malicious users to make logged-in users perform unwanted actions.
Digitialpixies Oauth Client
7.5
CVSSv2
CVE-2015-9435
The oauth2-provider plugin prior to 3.1.5 for WordPress has incorrect generation of random numbers.
Dash10 Oauth Server
NA
CVE-2022-3631
The OAuth Client by DigitialPixies WordPress plugin up to and including 1.1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disall...
Digitialpixies Oauth Client
5.8
CVSSv2
CVE-2019-10372
An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and previous versions in GitLabSecurityRealm.java allows malicious users to redirect users to a URL outside Jenkins after successful login.
Jenkins Gitlab Oauth
NA
CVE-2023-33005
Jenkins WSO2 Oauth Plugin 1.0 and previous versions does not invalidate the previous session on login.
Jenkins Wso2 Oauth
NA
CVE-2023-30527
Jenkins WSO2 Oauth Plugin 1.0 and previous versions stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Jenkins Wso2 Oauth
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »