131 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2020-27986
Software Genérico DevOps Web ⚡ nuclei
7.5
HIGH
EPSS
92.6%
2020 0 PoCs

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for SMTP and SVN is "it is the administrator's responsibility to configure it.

CVE-2020-13290
GitLab DevOps
7.5
HIGH
EPSS
0.2%
2020 1 PoC

In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page

CVE-2020-14589
WebLogic Server DevOps Web Database
7.5
HIGH
EPSS
3.2%
2020 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/

CVE-2020-35558
Software Genérico DevOps Database
7.5
HIGH
EPSS
0.3%
2020 1 PoC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in the in the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials.

CVE-2020-13270
GitLab DevOps Web
7.5
HIGH
EPSS
0.4%
2020 1 PoC

Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API

CVE-2020-13343
GitLab DevOps
7.5
HIGH
EPSS
0.1%
2020 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template

CVE-2020-13285
GitLab DevOps Web
7.3
HIGH
EPSS
0.1%
2020 1 PoC

For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.

CVE-2020-12525
fdtCONTAINER Component DevOps
7.3
HIGH
EPSS
0.1%
2020 CWE-502 1 PoC

M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

CVE-2020-13337
GitLab DevOps Web
7.2
HIGH
EPSS
0.1%
2020 1 PoC

An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name.

CVE-2020-13303
GitLab DevOps
7.1
HIGH
EPSS
0.1%
2020 1 PoC

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project.

CVE-2020-1706
openshift/apb-tools-container DevOps
7.0
HIGH
EPSS
0.1%
2020 CWE-732 1 PoC

It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/apb-tools-container.

CVE-2020-1709
openshift/mediawiki DevOps
7.0
HIGH
EPSS
0.0%
2020 CWE-732 1 PoC

A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the openshift/mediawiki. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.

CVE-2020-1707
openshift/postgresql-apb DevOps Database
7.0
HIGH
EPSS
0.0%
2020 CWE-732 1 PoC

A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/postgresql-apb. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.

CVE-2020-14557
WebLogic Server DevOps Web Database
6.8
MEDIUM
EPSS
1.9%
2020 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well a

CVE-2020-13324
GitLab DevOps Web
6.5
MEDIUM
EPSS
0.1%
2020 1 PoC

A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.

CVE-2020-13296
GitLab DevOps
6.5
MEDIUM
EPSS
0.3%
2020 1 PoC

An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens

CVE-2020-12527
mymbCONNECT24 DevOps
6.5
MEDIUM
EPSS
0.1%
2020 CWE-269 1 PoC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to shutdown or reboot devices in his account without having corresponding permissions.

CVE-2020-35557
Software Genérico DevOps
6.5
MEDIUM
EPSS
0.3%
2020 1 PoC

An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation.

CVE-2020-13351
GitLab CE/EE DevOps Web
6.5
MEDIUM
EPSS
0.3%
2020 2 PoCs

Insufficient permission checks in scheduled pipeline API in GitLab CE/EE 13.0+ allows an attacker to read variable names and values for scheduled pipelines on projects visible to the attacker. Affected versions are >=13.0, <13.3.9,>=13.4.0, <13.4.5,>=13.5.0, <13.5.2.

CVE-2020-13346
GitLab DevOps Web
6.5
MEDIUM
EPSS
0.2%
2020 1 PoC

Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.