13 vulnerabilidades · DevOps · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2020-17496
🔥 KEV Software Genérico DevOps ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2020 4 PoCs

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.

CVE-2020-11854
Application Performance Management DevOps ⚡ nuclei
9.8
CRITICAL
EPSS
92.4%
2020 1 PoC

Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) vulnerability in Micro Focus products products Operation Bridge Manager, Operation Bridge (containerized) and Application Performance Management. The vulneravility affects: 1.) Operation Bridge Manager versions 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, 10.63,10.62, 10.61, 10.60, 10.12, 10.11, 10.10 and all earlier versions. 2.) Operations Bridge (containerized) 2020.05, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05. 2018.02 and 2017.11. 3.) Application Pe

CVE-2020-11853
Operation Bridge Manager DevOps ⚡ nuclei
8.8
HIGH
EPSS
92.7%
2020 3 PoCs

Arbitrary code execution vulnerability affecting multiple Micro Focus products. 1.) Operation Bridge Manager affecting version: 2020.05, 2019.11, 2019.05, 2018.11, 2018.05, versions 10.6x and 10.1x and older versions. 2.) Application Performance Management affecting versions : 9.51, 9.50 and 9.40 with uCMDB 10.33 CUP 3 3.) Data Center Automation affected version 2019.11 4.) Operations Bridge (containerized) affecting versions: 2019.11, 2019.08, 2019.05, 2018.11, 2018.08, 2018.05, 2018.02, 2017.11 5.) Universal CMDB affecting version: 2020.05, 2019.11, 2019.05, 2019.02, 2018.11, 2018.08, 2018.0

CVE-2020-27986
Software Genérico DevOps Web ⚡ nuclei
7.5
HIGH
EPSS
92.6%
2020 0 PoCs

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.

CVE-2020-26413
GitLab CE/EE DevOps ⚡ nuclei
5.3
MEDIUM
EPSS
82.1%
2020 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

CVE-2020-16248
Software Genérico DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
3.6%
2020 0 PoCs

Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability

CVE-2020-2096
Jenkins Gitlab Hook Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2020 1 PoC

Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.

CVE-2020-11710
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2020 1 PoC

An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “1) Inaccurate Bug Scope - The issue scope was on Kong's docker-compose template, and not Kong's docker image itself. In reality, this issue is not associated with any version of the Kong gateway. As such, the description stating ‘An issue was discovered in docker-kong (for Kong) through 2.0.3.’ is incorrect. This issue only occurs if a user de

CVE-2020-11110
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
54.0%
2020 1 PoC

Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot.

CVE-2020-2103
Jenkins DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
45.2%
2020 0 PoCs

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.

CVE-2020-9757
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2020 0 PoCs

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.

CVE-2020-2140
Jenkins Audit Trail Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
44.8%
2020 0 PoCs

Jenkins Audit Trail Plugin 3.2 and earlier does not escape the error message for the URL Patterns field form validation, resulting in a reflected cross-site scripting vulnerability.

CVE-2020-13379
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2020 4 PoCs

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.