513 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2020-35570
Software Genérico DevOps
5.3
MEDIUM
EPSS
0.8%
2020 1 PoC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing.

CVE-2022-36109
moby DevOps
5.3
MEDIUM
EPSS
0.0%
2022 CWE-863 1 PoC

Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. This bug is fixed in Moby (Docker Engine) 20.10.18. Running containers should be stopped and restarted for the

CVE-2023-6001
YugabyteDB Anywhere DevOps
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.

CVE-2024-2191
GitLab DevOps
5.3
MEDIUM
EPSS
0.2%
2024 CWE-284 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

CVE-2020-7693
sockjs DevOps
5.3
MEDIUM
EPSS
16.0%
2020 2 PoCs

Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.

CVE-2020-35566
Software Genérico DevOps
5.3
MEDIUM
EPSS
0.2%
2020 1 PoC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An attacker can read arbitrary JSON files via Local File Inclusion.

CVE-2020-35561
Software Genérico DevOps
5.3
MEDIUM
EPSS
0.8%
2020 1 PoC

An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allowing an unauthenticated attacker to scan for open ports.

CVE-2020-26413
GitLab CE/EE DevOps ⚡ nuclei
5.3
MEDIUM
EPSS
82.1%
2020 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

CVE-2022-2531
GitLab DevOps Web
5.3
MEDIUM
EPSS
0.7%
2022 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was not performing correct authentication on Grafana API under specific conditions allowing unauthenticated users to perform queries through a path traversal vulnerability.

CVE-2022-1148
GitLab DevOps
5.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to steal a user's access token on an attacker-controlled private GitLab Pages website and reuse that token on the victim's other private websites

CVE-2021-22167
GitLab DevOps
5.3
MEDIUM
EPSS
0.2%
2021 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 12.1. Incorrect headers in specific project page allows attacker to have a temporary read access to the private repository

CVE-2023-3932
GitLab DevOps
5.3
MEDIUM
EPSS
0.1%
2023 CWE-286 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies.

CVE-2021-22248
GitLab DevOps
5.3
MEDIUM
EPSS
0.2%
2021 1 PoC

Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only

CVE-2021-4191
GitLab DevOps Web ⚡ nuclei
5.3
MEDIUM
EPSS
92.1%
2021 2 PoCs

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with restricted sign-ups may be vulnerable to user enumeration to unauthenticated users through the GraphQL API.

CVE-2024-37152
argo-cd DevOps Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
80.2%
2024 CWE-287 0 PoCs

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.

CVE-2023-34040
Spring For Apache Kafka DevOps Web
5.3
MEDIUM
EPSS
21.4%
2023 CWE-502 4 PoCs

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an application is vulnerable when all of the following are true: * The user does not configure an ErrorHandlingDeserializer for the key and/or value of the record * The user explicitly sets container properties checkDeserExWhenKeyNull and/or checkDeserExWhenValueNull container pro

CVE-2021-22210
GitLab DevOps Web
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.

CVE-2022-21616
WebLogic Server DevOps Database
5.2
MEDIUM
EPSS
0.0%
2022 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server as well as unauthorized update, insert or delete access to some of Oracl

CVE-2023-31001
Security Verify Access Appliance DevOps
5.1
MEDIUM
EPSS
0.0%
2023 CWE-257 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.6.1) temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254653.

CVE-2024-8118
Grafana DevOps Web
5.1
MEDIUM
EPSS
0.1%
2024 CWE-653 1 PoC

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.