513 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2023-2164
GitLab DevOps Web
5.4
MEDIUM
EPSS
52.2%
2023 CWE-79 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

CVE-2023-3914
GitLab DevOps
5.4
MEDIUM
EPSS
0.0%
2023 CWE-286 1 PoC

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

CVE-2023-1265
GitLab DevOps
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.

CVE-2023-3115
GitLab DevOps
5.4
MEDIUM
EPSS
0.0%
2023 CWE-286 1 PoC

An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.

CVE-2024-41968
CC100 0751-9x01 DevOps
5.4
MEDIUM
EPSS
0.6%
2024 CWE-306 1 PoC

A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.

CVE-2024-8647
GitLab DevOps Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-22 1 PoC

An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.

CVE-2020-13338
GitLab DevOps Web
5.4
MEDIUM
EPSS
0.1%
2020 1 PoC

An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.

CVE-2020-13331
GitLab DevOps Web
5.4
MEDIUM
EPSS
0.1%
2020 1 PoC

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.

CVE-2020-13316
GitLab DevOps
5.4
MEDIUM
EPSS
0.3%
2020 2 PoCs

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.

CVE-2020-8558
Kubernetes DevOps
5.4
MEDIUM
EPSS
20.1%
2020 CWE-420 1 PoC

The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.

CVE-2022-41242
Jenkins extreme-feedback Plugin DevOps
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps, and rename lamps.

CVE-2023-3932
GitLab DevOps
5.3
MEDIUM
EPSS
0.1%
2023 CWE-286 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVE-2023-34040
Spring For Apache Kafka DevOps Web
5.3
MEDIUM
EPSS
21.4%
2023 CWE-502 4 PoCs

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an application is vulnerable when all of the following are true: * The user does not configure an ErrorHandlingDeserializer for the key and/or value of the record * The user explicitly sets container properties checkDeserExWhenKeyNull and/or checkDeserExWhenValueNull container pro

CVE-2023-5612
GitLab DevOps
5.3
MEDIUM
EPSS
25.6%
2023 CWE-862 2 PoCs

An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

CVE-2023-6001
YugabyteDB Anywhere DevOps
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.

CVE-2023-25173
containerd DevOps
5.3
MEDIUM
EPSS
0.0%
2023 CWE-863 1 PoC

containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. Downstream applications that use the containerd client library may be affected as well. This bug has be

CVE-2023-4002
GitLab DevOps
5.3
MEDIUM
EPSS
0.1%
2023 CWE-201 2 PoCs

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

CVE-2023-31416
Elastic Cloud on Kubernetes DevOps Cloud
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.

CVE-2024-37152
argo-cd DevOps Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
80.2%
2024 CWE-287 0 PoCs

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.

CVE-2024-8650
GitLab DevOps
5.3
MEDIUM
EPSS
0.2%
2024 CWE-863 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.