513 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2021-22225
GitLab DevOps Web
4.7
MEDIUM
EPSS
0.1%
2021 1 PoC

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

CVE-2025-10282
bbot DevOps Web
4.7
MEDIUM
EPSS
0.0%
2025 CWE-200 1 PoC

BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL.

CVE-2025-5054
Apport DevOps
4.7
MEDIUM
EPSS
0.0%
2025 CWE-362 3 PoCs

Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function `_check_global_pid_and_forward`, which detects if the crashing process resided in a container, was being called before `consistency_checks`, which attempts to detect if the crashing process had been replaced. Because of this, if a process crashed and was quickly replaced with a containerized one, apport could be made to forward the core dump to the container, potentially leaking sensitive information.

CVE-2020-8565
Kubernetes DevOps Web
4.7
MEDIUM
EPSS
0.1%
2020 CWE-532 1 PoC

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

CVE-2020-8563
Kubernetes DevOps Cloud
4.7
MEDIUM
EPSS
0.1%
2020 CWE-532 1 PoC

In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.

CVE-2018-2415
SAP NetWeaver Application Server (Engine API) DevOps Web
4.7
MEDIUM
EPSS
0.3%
2018 1 PoC

SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40, 7.50) do not sufficiently encode user controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed.

CVE-2022-3486
GitLab DevOps
4.7
MEDIUM
EPSS
0.4%
2022 2 PoCs

An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVE-2022-2250
GitLab DevOps
4.7
MEDIUM
EPSS
0.3%
2022 1 PoC

An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVE-2023-30714
Samsung Mobile Devices DevOps
4.6
MEDIUM
EPSS
0.1%
2023 1 PoC

Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.

CVE-2024-40635
containerd DevOps
4.6
MEDIUM
EPSS
0.1%
2024 CWE-190 1 PoC

containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This could cause unexpected behavior for environments that require containers to run as a non-root user. This bug has been fixed in containerd 1.6.38, 1.7.27, and 2.04. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

CVE-2021-47831
Sandboxie DevOps
4.6
MEDIUM
EPSS
0.0%
2021 CWE-1284 1 PoC

Sandboxie 5.49.7 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the container folder input field. Attackers can paste a large buffer of repeated characters into the Sandbox container folder setting to trigger an application crash.

CVE-2022-3205
Red Hat Ansible Automation Platform 1.2 DevOps Web
4.6
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection

CVE-2023-2485
GitLab DevOps
4.4
MEDIUM
EPSS
0.2%
2023 CWE-266 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of.

CVE-2023-5995
GitLab DevOps
4.4
MEDIUM
EPSS
0.0%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

CVE-2023-1836
GitLab DevOps Web
4.4
MEDIUM
EPSS
1.0%
2023 1 PoC

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. When viewing an XML file in a repository in "raw" mode, it can be made to render as HTML if viewed under specific circumstances

CVE-2024-4201
GitLab DevOps Web
4.4
MEDIUM
EPSS
1.1%
2024 CWE-79 1 PoC

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVE-2024-8266
GitLab DevOps
4.4
MEDIUM
EPSS
0.1%
2024 CWE-250 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.

CVE-2020-13330
GitLab DevOps Web
4.4
MEDIUM
EPSS
0.1%
2020 1 PoC

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in import the Bitbucket project feature.

CVE-2023-3917
GitLab DevOps
4.3
MEDIUM
EPSS
0.2%
2023 CWE-1287 1 PoC

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

CVE-2023-4532
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of private projects which they are not a member of.