113 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2023-49096
jellyfin DevOps
7.7
HIGH
EPSS
1.4%
2023 CWE-88 1 PoC

Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument injection in the VideosController, specifically the `/Videos/<itemId>/stream` and `/Videos/<itemId>/stream.<container>` endpoints which are present in the current Jellyfin version. Additional endpoints in the AudioController might also be vulnerable, as they differ only slightly in execution. Those endpoints are reachable by an unauthenticated user. In order to exploit this vulnerability an unauthenticated attacker has to guess an itemId, which is a completely random GUID. It’s

CVE-2023-5044
ingress-nginx DevOps Web
7.6
HIGH
EPSS
10.6%
2023 CWE-20 3 PoCs

Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

CVE-2023-38370
Security Access Manager Docker DevOps
7.5
HIGH
EPSS
0.0%
2023 CWE-276 2 PoCs

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.

CVE-2023-26031
Apache Hadoop DevOps Web
7.5
HIGH
EPSS
9.3%
2023 CWE-426 3 PoCs

Relative library resolution in linux container-executor binary in Apache Hadoop 3.3.1-3.3.4 on Linux allows local user to gain root privileges. If the YARN cluster is accepting work from remote (authenticated) users, this MAY permit remote users to gain root privileges. Hadoop 3.3.0 updated the " YARN Secure Containers https://hadoop.apache.org/docs/stable/hadoop-yarn/hadoop-yarn-site/SecureContainer.html " to add a feature for executing user-submitted applications in isolated linux containers. The native binary HADOOP_HOME/bin/container-executor is used to launch these containers; it must b

CVE-2023-32077
netmaker DevOps Web ⚡ nuclei
7.5
HIGH
EPSS
86.6%
2023 CWE-321 0 PoCs

Netmaker makes networks with WireGuard. Prior to versions 0.17.1 and 0.18.6, hardcoded DNS key usage has been found in Netmaker allowing unauth users to interact with DNS API endpoints. The issue is patched in 0.17.1 and fixed in 0.18.6. If users are using 0.17.1, they should run `docker pull gravitl/netmaker:v0.17.1` and `docker-compose up -d`. This will switch them to the patched users. If users are using v0.18.0-0.18.5, they should upgrade to v0.18.6 or later. As a workaround, someone who is using version 0.17.1 can pull the latest docker image of the backend and restart the server.

CVE-2023-21842
WebLogic Server DevOps Web Database
7.5
HIGH
EPSS
1.1%
2023 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2023-30999
Security Verify Access Appliance DevOps
7.5
HIGH
EPSS
0.1%
2023 CWE-400 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an attacker to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 254651.

CVE-2023-42005
Db2 on Cloud Pak for Data DevOps Cloud
7.4
HIGH
EPSS
0.1%
2023 CWE-264 1 PoC

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a user with access to the Kubernetes pod, to make system calls compromising the security of containers. IBM X-Force ID: 265264.

CVE-2023-22480
KubeOperator DevOps Web ⚡ nuclei
7.3
HIGH
EPSS
75.6%
2023 CWE-285 0 PoCs

KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This vulnerability could be used to take over the cluster under certain conditions. This issue has been patched in version 3.16.4.

CVE-2023-22478
KubePi DevOps Web ⚡ nuclei
7.3
HIGH
EPSS
81.1%
2023 CWE-862 0 PoCs

KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in version 1.6.4. There are currently no known workarounds.

CVE-2023-3971
Red Hat Ansible Automation Platform 2.3 for RHEL 8 DevOps
7.3
HIGH
EPSS
0.4%
2023 CWE-80 1 PoC

An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.

CVE-2023-43016
Security Verify Access Appliance DevOps
7.3
HIGH
EPSS
0.2%
2023 CWE-258 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a remote user to log into the server due to a user account with an empty password. IBM X-Force ID: 266154.

CVE-2023-32327
Security Verify Access Appliance DevOps
7.1
HIGH
EPSS
0.0%
2023 CWE-611 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 254783.

CVE-2023-44090
Pandora FMS DevOps Database
6.8
MEDIUM
EPSS
0.1%
2023 CWE-89 1 PoC

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows CVE-2008-5817. This vulnerability allowed SQL changes to be made to several files in the Grafana module. This issue affects Pandora FMS: from 700 through <776.

CVE-2023-1965
GitLab DevOps
6.8
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 14.2 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Lack of verification on RelayState parameter allowed a maliciously crafted URL to obtain access tokens granted for 3rd party Group SAML SSO logins. This feature isn't enabled by default.

CVE-2023-6840
GitLab DevOps
6.7
MEDIUM
EPSS
0.0%
2023 CWE-862 1 PoC

An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.

CVE-2023-3441
GitLab DevOps
6.6
MEDIUM
EPSS
0.1%
2023 CWE-213 1 PoC

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.

CVE-2023-31006
Security Verify Access Appliance DevOps
6.5
MEDIUM
EPSS
0.0%
2023 CWE-400 1 PoC

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to a denial of service attacks on the DSC server. IBM X-Force ID: 254776.

CVE-2023-47430
Software Genérico DevOps
6.5
MEDIUM
EPSS
0.0%
2023 1 PoC

Stack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer() function at tivo_commands.c.

CVE-2023-20235
Cisco IOS XE Software DevOps Networking
6.5
MEDIUM
EPSS
0.2%
2023 CWE-552 1 PoC

A vulnerability in the on-device application development workflow feature for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an authenticated, remote attacker to access the underlying operating system as the root user. This vulnerability exists because Docker containers with the privileged runtime option are not blocked when they are in application development mode. An attacker could exploit this vulnerability by using the Docker CLI to access an affected device. The application development workflow is meant to be used only on development systems and n