9 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2022-0735
GitLab DevOps ⚡ nuclei
10.0
CRITICAL
EPSS
57.4%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVE-2022-2992
GitLab DevOps Web
9.9
CRITICAL
EPSS
93.7%
2022 3 PoCs

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

CVE-2022-2185
GitLab DevOps ⚡ nuclei
9.9
CRITICAL
EPSS
90.1%
2022 3 PoCs

A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.

CVE-2022-2884
GitLab DevOps Web
9.9
CRITICAL
EPSS
69.0%
2022 3 PoCs

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVE-2022-46071
Software Genérico DevOps Database ⚡ nuclei
9.8
CRITICAL
EPSS
79.2%
2022 2 PoCs

There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.

CVE-2022-46072
Software Genérico DevOps Database
9.8
CRITICAL
EPSS
1.5%
2022 2 PoCs

Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.

CVE-2022-45933
Software Genérico DevOps Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2022 0 PoCs

KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."

CVE-2022-39395
server DevOps
9.6
CRITICAL
EPSS
3.7%
2022 CWE-269 1 PoC

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela Server and Vela Worker prior to version 0.16.0 and Vela UI prior to version 0.17.0, some default configurations for Vela allow exploitation and container breakouts. Users should upgrade to Server 0.16.0, Worker 0.16.0, and UI 0.17.0 to fix the issue. After upgrading, Vela administrators will need to explicitly change the default settings to configure Vela as desired. Some of the fixes will interrupt existing workflows and will require Vela administrators to modify default settings. Ho

CVE-2022-1162
GitLab DevOps Windows ⚡ nuclei
9.1
CRITICAL
EPSS
87.6%
2022 3 PoCs

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts