92 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2021-21382
restund DevOps Web
8.6
HIGH
EPSS
0.5%
2021 CWE-668 2 PoCs

Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopback address range. This allows you to reach any other service running on localhost which you might consider private. In the configuration that we ship (https://github.com/wireapp/ansible-restund/blob/master/templates/restund.conf.j2#L40-L43) the `status` interface of restund is enabled and is listening on `127.0.0.1`.The `status` interface allows users to issue administrative commands to `restund` like listing open relays or draining connections. It would be possible for an att

CVE-2021-22195
gitlab-vscode-extension DevOps
8.6
HIGH
EPSS
0.2%
2021 1 PoC

Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system

CVE-2021-43050
TIBCO BusinessConnect Container Edition DevOps
8.4
HIGH
EPSS
0.0%
2021 1 PoC

The Auth Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Container Edition contains an easily exploitable vulnerability that allows an unauthenticated attacker with local access to obtain administrative usernames and passwords for the affected system. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Container Edition: versions 1.1.0 and below.

CVE-2021-33183
Synology Docker DevOps
7.9
HIGH
EPSS
0.1%
2021 CWE-22 1 PoC

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management component in Synology Docker before 18.09.0-0515 allows local users to read or write arbitrary files via unspecified vectors.

CVE-2021-31165
Windows 10 Version 2004 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-31169
Windows 10 Version 2004 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-31168
Windows 10 Version 2004 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-31167
Windows 10 Version 1809 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 2 PoCs

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-39877
GitLab DevOps
7.7
HIGH
EPSS
0.2%
2021 1 PoC

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

CVE-2021-43798
🔥 KEV grafana DevOps Cloud ⚡ nuclei
7.5
HIGH
EPSS
94.4%
2021 CWE-22 54 PoCs

Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline.

CVE-2021-35497
TIBCO ActiveSpaces - Community Edition DevOps
7.5
HIGH
EPSS
0.2%
2021 1 PoC

The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, TIBCO ActiveSpaces - Enterprise Edition, TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, TIBCO FTL - Enterprise Edition, TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contain a vulnerability that theoretically allows a non-administrative, authenticated FTL user to trick the affected components into creating illegitimate certificates. These ma

CVE-2021-40476
Windows 10 Version 1809 DevOps Windows
7.5
HIGH
EPSS
0.4%
2021 1 PoC

Windows AppContainer Elevation Of Privilege Vulnerability

CVE-2021-22261
GitLab DevOps Web
7.3
HIGH
EPSS
0.2%
2021 1 PoC

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVE-2021-22171
GitLab DevOps Web
7.3
HIGH
EPSS
0.1%
2021 1 PoC

Insufficient validation of authentication parameters in GitLab Pages for GitLab 11.5+ allows an attacker to steal a victim's API token if they click on a maliciously crafted link

CVE-2021-22224
GitLab DevOps Web
7.1
HIGH
EPSS
0.4%
2021 1 PoC

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

CVE-2021-41174
grafana DevOps Web ⚡ nuclei
6.9
MEDIUM
EPSS
87.7%
2021 CWE-79 0 PoCs

Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, arbitrary JavaScript content may be executed within the context of the victim's browser. The user visiting the malicious link must be unauthenticated and the link must be for a page that contains the login button in the menu bar. The url has to be crafted to exploit AngularJS rendering and contain the interpolation binding for AngularJS expressions. AngularJS uses double curly braces for interpolation binding: {{ }}

CVE-2021-22175
🔥 KEV GitLab DevOps ⚡ nuclei
6.8
MEDIUM
EPSS
69.7%
2021 1 PoC

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

CVE-2021-22214
GitLab DevOps ⚡ nuclei
6.8
MEDIUM
EPSS
93.3%
2021 7 PoCs

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVE-2021-22206
GitLab DevOps
6.8
MEDIUM
EPSS
0.1%
2021 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,

CVE-2021-22238
GitLab DevOps Web
6.8
MEDIUM
EPSS
1.2%
2021 1 PoC

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.