9 vulnerabilidades · DevOps · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-0735
GitLab DevOps ⚡ nuclei
10.0
CRITICAL
EPSS
57.4%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVE-2022-2185
GitLab DevOps ⚡ nuclei
9.9
CRITICAL
EPSS
90.1%
2022 3 PoCs

A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.

CVE-2022-46071
Software Genérico DevOps Database ⚡ nuclei
9.8
CRITICAL
EPSS
79.2%
2022 2 PoCs

There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.

CVE-2022-45933
Software Genérico DevOps Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2022 0 PoCs

KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."

CVE-2022-1162
GitLab DevOps Windows ⚡ nuclei
9.1
CRITICAL
EPSS
87.6%
2022 3 PoCs

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVE-2022-21371
WebLogic Server DevOps Web Database ⚡ nuclei
7.5
HIGH
EPSS
93.4%
2022 5 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

CVE-2022-46073
Software Genérico DevOps Web ⚡ nuclei
6.1
MEDIUM
EPSS
29.5%
2022 2 PoCs

Helmet Store Showroom 1.0 is vulnerable to Cross Site Scripting (XSS).

CVE-2022-26148
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.2%
2022 0 PoCs

An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to discover the Zabbix account password and URL address.

CVE-2022-36883
Jenkins Git Plugin DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
78.6%
2022 0 PoCs

A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds of jobs configured to use an attacker-specified Git repository and to cause them to check out an attacker-specified commit.