513 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2022-29170
grafana DevOps Web
6.6
MEDIUM
EPSS
0.1%
2022 CWE-601 1 PoC

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with version 7.4.0-beta1 and prior to versions 7.5.16 and 8.5.3 allows someone to bypass these security configurations if a malicious datasource (running on an allowed host) returns an HTTP redirect to a forbidden host. The vulnerability only impacts Grafana Enterprise when the Request security allow list is used and there is a p

CVE-2022-3294
Kubernetes DevOps Web
6.6
MEDIUM
EPSS
0.5%
2022 CWE-20 1 PoC

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server'

CVE-2026-1458
GitLab DevOps
6.5
MEDIUM
EPSS
0.0%
2026 CWE-770 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.

CVE-2026-1456
GitLab DevOps
6.5
MEDIUM
EPSS
0.0%
2026 CWE-770 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.

CVE-2023-47430
Software Genérico DevOps
6.5
MEDIUM
EPSS
0.0%
2023 1 PoC

Stack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer() function at tivo_commands.c.

CVE-2023-3413
GitLab DevOps
6.5
MEDIUM
EPSS
0.2%
2023 CWE-201 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to read the source code of a project through a fork created before changing visibility to only project members.

CVE-2023-31006
Security Verify Access Appliance DevOps
6.5
MEDIUM
EPSS
0.0%
2023 CWE-400 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to a denial of service attacks on the DSC server. IBM X-Force ID: 254776.

CVE-2023-1621
GitLab DevOps
6.5
MEDIUM
EPSS
1.9%
2023 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.5, all versions starting from 15.11 before 15.11.1. A malicious group member may continue to commit to projects even from a restricted IP address.

CVE-2023-20235
Cisco IOS XE Software DevOps Networking
6.5
MEDIUM
EPSS
0.2%
2023 CWE-552 1 PoC

A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system as the root user. This vulnerability exists because Docker containers with the privileged runtime option are not blocked when they are in application development mode. An attacker could exploit this vulnerability by using the Docker CLI to access an affected device. The application development workflow is meant to be used only on development systems and n

CVE-2024-12379
GitLab DevOps
6.5
MEDIUM
EPSS
0.1%
2024 CWE-770 1 PoC

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.

CVE-2024-42364
homepage DevOps Web
6.5
MEDIUM
EPSS
0.1%
2024 CWE-350 1 PoC

Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is setup without certificate and authentication by default, leaving it to vulnerable to DNS rebinding. In this attack, an attacker will ask a user to visit his/her website. The attacker website will then change the DNS records of their domain from their IP address to the internal IP address of the homepage instance. To tell which IP addresses are valid, we can rebind a subdomain to each IP address we want to check, and see if there is

CVE-2024-55963
Software Genérico DevOps Web
6.5
MEDIUM
EPSS
37.2%
2024 1 PoC

An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of service because it can be continually restarted. This is due to incorrect access control checks, which should check for super user permissions on the incoming request.

CVE-2024-3959
GitLab DevOps
6.5
MEDIUM
EPSS
0.0%
2024 CWE-285 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.

CVE-2024-1963
GitLab DevOps
6.5
MEDIUM
EPSS
0.2%
2024 CWE-1333 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.4 prior to 16.10.7, starting from 16.11 prior to 16.11.4, and starting from 17.0 prior to 17.0.2. A vulnerability in GitLab's Asana integration allowed an attacker to potentially cause a regular expression denial of service by sending specially crafted requests.

CVE-2024-41454
Software Genérico DevOps Web
6.5
MEDIUM
EPSS
0.6%
2024 2 PoCs

An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary code via uploading a crafted PHP or HTML file.

CVE-2024-4210
GitLab DevOps
6.5
MEDIUM
EPSS
0.1%
2024 CWE-400 1 PoC

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files.

CVE-2024-10219
GitLab DevOps Web
6.5
MEDIUM
EPSS
0.0%
2024 CWE-863 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.

CVE-2019-11248
Kubernetes DevOps ⚡ nuclei
6.5
MEDIUM
EPSS
91.0%
2019 CWE-419 1 PoC

The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.

CVE-2021-29622
prometheus DevOps ⚡ nuclei
6.5
MEDIUM
EPSS
86.7%
2021 CWE-601 0 PoCs

Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seamless transition, the URL's prefixed by /new redirect to /. Due to a bug in the code, it is possible for an attacker to craft an URL that can redirect to any other URL, in the /new endpoint. If a user visits a prometheus server with a specially crafted address, they can be redirected to an arbitrary URL. The issue was patched in the 2.26.1 and 2.27.1 releases. In 2.28.0, the /new endpoint will be removed completely. The workaround is to disable acc

CVE-2021-25735
Kubernetes DevOps Web
6.5
MEDIUM
EPSS
14.4%
2021 CWE-372 1 PoC

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.