513 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2022-1193
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances

CVE-2022-3030
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

CVE-2022-0125
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVE-2022-1174
GitLab DevOps
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVE-2026-1747
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2026 CWE-288 1 PoC

GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to protected Conan packages.

CVE-2026-0602
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2026 CWE-288 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose metadata from private issues, merge requests, epics, milestones, or commits due to improper filtering in the snippet rendering process under certain circumstances.

CVE-2019-3828
Ansible DevOps
4.2
MEDIUM
EPSS
0.0%
2019 CWE-22 1 PoC

Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.

CVE-2025-6197
Grafana DevOps ⚡ nuclei
4.2
MEDIUM
EPSS
0.6%
2025 CWE-601 0 PoCs

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

CVE-2020-13294
GitLab DevOps
4.2
MEDIUM
EPSS
0.3%
2020 1 PoC

In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.

CVE-2018-1002100
Kubernetes DevOps
4.2
MEDIUM
EPSS
0.5%
2018 1 PoC

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

CVE-2024-0134
NVIDIA Container Toolkit DevOps
4.1
MEDIUM
EPSS
0.2%
2024 CWE-61 1 PoC

NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.

CVE-2026-1230
GitLab DevOps
4.1
MEDIUM
EPSS
0.1%
2026 CWE-706 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due to incorrect validation of branch references under certain circumstances.

CVE-2024-5318
GitLab DevOps
4.0
MEDIUM
EPSS
0.0%
2024 CWE-862 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and starting from 17.0 prior to 17.0.1. A Guest user can view dependency lists of private projects through job artifacts.