Skip to main content

Vendor/product archive

sos-berlin / jobscheduler CVEs

Beta · best-effort

5 CVEs tagged to sos-berlin / jobscheduler0 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2023-37272

Published Jul 13, 2023

JS7 is an Open Source Job Scheduler. Users specify file names when uploading files holding user-generated documentation for JOC Cockpit. Specifically crafted file names allow an X…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12712

Published Jun 11, 2020

A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6856

Published Feb 6, 2020

An XML External Entity (XEE) vulnerability exists in the JOC Cockpit component of SOS JobScheduler 1.12 and 1.13.2 allows attackers to read files from the server via an entity dec…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6855

Published Feb 6, 2020

A large or infinite loop vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to parameterize housekeeping jobs in a way that exhausts s…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6854

Published Feb 5, 2020

A cross-site scripting (XSS) vulnerability in the JOC Cockpit component of SOS JobScheduler 1.11 and 1.13.2 allows attackers to inject arbitrary web script or HTML via JSON proper…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1