513 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2023-3920
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVE-2023-3900
GitLab DevOps
4.3
MEDIUM
EPSS
0.2%
2023 CWE-1287 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

CVE-2023-6489
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2023 CWE-1333 1 PoC

A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.

CVE-2023-5198
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.

CVE-2023-1417
GitLab DevOps
4.3
MEDIUM
EPSS
0.6%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group.

CVE-2023-3964
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.

CVE-2023-3904
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2023 CWE-1287 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

CVE-2023-2022
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-262 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

CVE-2023-21419
Samsung Mobile Devices DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-287 1 PoC

An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition.

CVE-2023-4018
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-425 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects.

CVE-2024-3825
BlazeMeter Jenkins plugin DevOps
4.3
MEDIUM
EPSS
0.2%
2024 CWE-352 1 PoC

Versions of the BlazeMeter Jenkins plugin prior to 4.22 contain a flaw which results in credential enumeration

CVE-2024-9367
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2024 CWE-770 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.

CVE-2024-12244
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2024 CWE-862 1 PoC

An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.

CVE-2024-3127
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2024 CWE-284 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.

CVE-2024-0861
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2024 CWE-425 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom dashboard projects` settings contrary to permissions.

CVE-2019-6744
Knox DevOps Cloud
4.3
MEDIUM
EPSS
0.1%
2019 CWE-284 1 PoC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the device in order to exploit this vulnerability. The specific flaws exists within the the handling of the lock screen for Secure Folder. The issue results from the lack of proper validation that a user has correctly authenticated. An attacker can leverage this vulnerability to disclose the contents of the secure container. Was ZDI-CAN-7381.

CVE-2021-39905
GitLab DevOps Web
4.3
MEDIUM
EPSS
0.3%
2021 1 PoC

An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic information on private groups that a public project has been shared with

CVE-2021-22176
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2021 1 PoC

An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

CVE-2021-39884
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2021 1 PoC

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVE-2021-39868
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2021 1 PoC

In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.