73 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2022-0735
GitLab DevOps ⚡ nuclei
10.0
CRITICAL
EPSS
57.4%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVE-2022-2185
GitLab DevOps ⚡ nuclei
9.9
CRITICAL
EPSS
90.1%
2022 3 PoCs

A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.

CVE-2022-2992
GitLab DevOps Web
9.9
CRITICAL
EPSS
93.7%
2022 3 PoCs

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

CVE-2022-2884
GitLab DevOps Web
9.9
CRITICAL
EPSS
69.0%
2022 3 PoCs

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVE-2022-46072
Software Genérico DevOps Database
9.8
CRITICAL
EPSS
1.5%
2022 2 PoCs

Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.

CVE-2022-45933
Software Genérico DevOps Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2022 0 PoCs

KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."

CVE-2022-46071
Software Genérico DevOps Database ⚡ nuclei
9.8
CRITICAL
EPSS
79.2%
2022 2 PoCs

There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.

CVE-2022-39395
server DevOps
9.6
CRITICAL
EPSS
3.7%
2022 CWE-269 1 PoC

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela Server and Vela Worker prior to version 0.16.0 and Vela UI prior to version 0.17.0, some default configurations for Vela allow exploitation and container breakouts. Users should upgrade to Server 0.16.0, Worker 0.16.0, and UI 0.17.0 to fix the issue. After upgrading, Vela administrators will need to explicitly change the default settings to configure Vela as desired. Some of the fixes will interrupt existing workflows and will require Vela administrators to modify default settings. Ho

CVE-2022-1162
GitLab DevOps Windows ⚡ nuclei
9.1
CRITICAL
EPSS
87.6%
2022 3 PoCs

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVE-2022-34374
Dell Container Storage Modules DevOps
8.8
HIGH
EPSS
4.9%
2022 CWE-78 1 PoC

Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to to execute arbitrary OS commands on the affected system.

CVE-2022-34375
Dell Container Storage Modules DevOps
8.8
HIGH
EPSS
0.4%
2022 CWE-22 1 PoC

Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintentional access to path outside of restricted directory.

CVE-2022-0071
Hotdog DevOps
8.8
HIGH
EPSS
0.0%
2022 CWE-250 1 PoC

Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or syscall filters of the target JVM process. This would allow a container to exhaust the resources of the host, modify devices, or make syscalls that would otherwise be blocked.

CVE-2022-46074
Software Genérico DevOps Web
8.8
HIGH
EPSS
0.3%
2022 2 PoCs

Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin account due to missing CSRF protection.

CVE-2022-38065
OpenStack DevOps
8.8
HIGH
EPSS
0.2%
2022 CWE-269 1 PoC

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

CVE-2022-38060
OpenStack DevOps
8.8
HIGH
EPSS
0.0%
2022 CWE-269 1 PoC

A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.

CVE-2022-31138
mailcow-dockerized DevOps
8.8
HIGH
EPSS
6.1%
2022 CWE-78 1 PoC

mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the custom parameters regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, or maxlinelengthcmd to execute arbitrary code. Users should update their mailcow instances with the `update.sh` script in the mailcow root directory to 2022-06a or newer to receive a patch for this issue. As a temporary workaround, the Syncjob ACL can be removed from all mailbox users, preventing changes to those settings.

CVE-2022-1175
GitLab DevOps Web
8.7
HIGH
EPSS
10.3%
2022 2 PoCs

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

CVE-2022-1948
GitLab DevOps Web
8.7
HIGH
EPSS
1.3%
2022 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

CVE-2022-31176
grafana-image-renderer DevOps Web
8.3
HIGH
EPSS
0.6%
2022 CWE-200 1 PoC

Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure vulnerability. It is possible for a malicious user to retrieve unauthorized files under some network conditions or via a fake datasource (if user has admin permissions in Grafana). All Grafana installations should be upgraded to version 3.6.1 as soon as possible. As a workaround it is possible to [disable HTTP remote rendering](https://grafana.com/docs/grafana/latest/setup-graf

CVE-2022-24812
grafana DevOps Web
8.0
HIGH
EPSS
0.3%
2022 CWE-269 1 PoC

Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization. Because of the way the cache ID is constructed, the consequent requests with any API Key evaluate to the same permissions as the previous requests. This can lead to an escalation of privileges, when for example a first request is made with Admin permissions, and the second request with different API Key is made with Viewer permissions, the second