261 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2024-0132
Container Toolkit DevOps
9.0
CRITICAL
EPSS
3.9%
2024 CWE-367 2 PoCs

NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-21400
Azure Kubernetes Service DevOps Cloud
9.0
CRITICAL
EPSS
1.6%
2024 CWE-22 1 PoC

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

CVE-2025-23266
Container Toolkit DevOps
9.0
CRITICAL
EPSS
0.1%
2025 CWE-426 7 PoCs

NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.

CVE-2023-24422
Jenkins Script Security Plugin DevOps
8.8
HIGH
EPSS
0.0%
2023 1 PoC

A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

CVE-2024-11075
SICK Incoming Goods Suite DevOps Networking
8.8
HIGH
EPSS
0.1%
2024 CWE-250 1 PoC

A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.

CVE-2024-22263
Spring Cloud Skipper DevOps Web Cloud
8.8
HIGH
EPSS
77.7%
2024 1 PoC

Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted upload request to write arbitrary file to any location on file system, may even compromises the server.

CVE-2024-43044
Jenkins DevOps
8.8
HIGH
EPSS
65.9%
2024 4 PoCs

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.

CVE-2024-24760
mailcow-dockerized DevOps
8.8
HIGH
EPSS
4.0%
2024 CWE-610 1 PoC

mailcow is a dockerized email package, with multiple containers linked in one bridged network. A security vulnerability has been identified in mailcow affecting versions < 2024-01c. This vulnerability potentially allows attackers on the same subnet to connect to exposed ports of a Docker container, even when the port is bound to 127.0.0.1. The vulnerability has been addressed by implementing additional iptables/nftables rules. These rules drop packets for Docker containers on ports 3306, 6379, 8983, and 12345, where the input interface is not `br-mailcow` and the output interface is `br-mailco

CVE-2019-5030
Antenna House DevOps
8.8
HIGH
EPSS
0.8%
2019 CWE-122 1 PoC

A buffer overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Document Converter V7.0 Pro MR1 (7,0,2019,0220). While parsing a document text info container, the TxMasterStyleAtom::parse function is incorrectly checking the bounds corresponding to the number of style levels, causing a vtable pointer to be overwritten, which leads to code execution.

CVE-2019-15789
MicroK8s DevOps
8.8
HIGH
EPSS
0.0%
2019 CWE-269 1 PoC

Privilege escalation vulnerability in MicroK8s allows a low privilege user with local access to obtain root access to the host by provisioning a privileged container. Fixed in MicroK8s 1.15.3.

CVE-2021-22213
GitLab DevOps Web
8.8
HIGH
EPSS
1.0%
2021 1 PoC

A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

CVE-2021-43858
minio DevOps Web Cloud
8.8
HIGH
EPSS
53.1%
2021 CWE-269 2 PoCs

MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version `RELEASE.2021-12-27T07-23-18Z` changes the accepted request body type and removes the ability to apply policy changes through this API. There is a workaround for this vulnerability: Changing passwords can be disabled by adding an explicit `Deny` rule to disable the API for users.

CVE-2021-3101
Hotdog DevOps
8.8
HIGH
EPSS
0.0%
2021 CWE-250 1 PoC

Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow a container to gain full privileges on the host, bypassing restrictions set on the container.

CVE-2021-25741
Kubernetes DevOps
8.8
HIGH
EPSS
33.0%
2021 CWE-20 2 PoCs

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

CVE-2025-24514
ingress-nginx DevOps Web ⚡ nuclei
8.8
HIGH
EPSS
51.6%
2025 CWE-20 2 PoCs

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

CVE-2025-1098
ingress-nginx DevOps Web ⚡ nuclei
8.8
HIGH
EPSS
36.0%
2025 CWE-20 1 PoC

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

CVE-2025-31722
Jenkins Templating Engine Plugin DevOps
8.8
HIGH
EPSS
1.1%
2025 1 PoC

In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.

CVE-2025-1097
ingress-nginx DevOps Web ⚡ nuclei
8.8
HIGH
EPSS
66.9%
2025 CWE-20 1 PoC

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

CVE-2020-11853
Operation Bridge Manager DevOps ⚡ nuclei
8.8
HIGH
EPSS
92.7%
2020 3 PoCs

Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.0

CVE-2022-31138
mailcow-dockerized DevOps
8.8
HIGH
EPSS
6.1%
2022 CWE-78 1 PoC

mailcow is a mailserver suite. Prior to mailcow-dockerized version 2022-06a, an extended privilege vulnerability can be exploited by manipulating the custom parameters regexmess, skipmess, regexflag, delete2foldersonly, delete2foldersbutnot, regextrans2, pipemess, or maxlinelengthcmd to execute arbitrary code. Users should update their mailcow instances with the `update.sh` script in the mailcow root directory to 2022-06a or newer to receive a patch for this issue. As a temporary workaround, the Syncjob ACL can be removed from all mailbox users, preventing changes to those settings.