1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2023-2164
GitLab DevOps Web
5.4
MEDIUM
EPSS
52.2%
2023 CWE-79 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.

CVE-2020-8558
Kubernetes DevOps
5.4
MEDIUM
EPSS
20.1%
2020 CWE-420 1 PoC

The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.

CVE-2023-3914
GitLab DevOps
5.4
MEDIUM
EPSS
0.0%
2023 CWE-286 1 PoC

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is not deleted when a namespace is deleted, allowing access to internal projects.

CVE-2023-1265
GitLab DevOps
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 11.9 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The condition allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.

CVE-2023-0155
GitLab DevOps
5.4
MEDIUM
EPSS
0.1%
2023 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown

CVE-2020-13316
GitLab DevOps
5.4
MEDIUM
EPSS
0.3%
2020 2 PoCs

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.

CVE-2023-3115
GitLab DevOps
5.4
MEDIUM
EPSS
0.0%
2023 CWE-286 1 PoC

An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.

CVE-2022-41242
Jenkins extreme-feedback Plugin DevOps
5.4
MEDIUM
EPSS
0.4%
2022 1 PoC

A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps, and rename lamps.

CVE-2024-41968
CC100 0751-9x01 DevOps
5.4
MEDIUM
EPSS
0.6%
2024 CWE-306 1 PoC

A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.

CVE-2023-7045
GitLab DevOps Web
5.4
MEDIUM
EPSS
0.1%
2023 CWE-352 1 PoC

A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS).

CVE-2020-13331
GitLab DevOps Web
5.4
MEDIUM
EPSS
0.1%
2020 1 PoC

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.

CVE-2024-2191
GitLab DevOps
5.3
MEDIUM
EPSS
0.2%
2024 CWE-284 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

CVE-2020-35561
Software Genérico DevOps
5.3
MEDIUM
EPSS
0.8%
2020 1 PoC

An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allowing an unauthenticated attacker to scan for open ports.

CVE-2020-35570
Software Genérico DevOps
5.3
MEDIUM
EPSS
0.8%
2020 1 PoC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing.

CVE-2023-25173
containerd DevOps
5.3
MEDIUM
EPSS
0.0%
2023 CWE-863 1 PoC

containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. Downstream applications that use the containerd client library may be affected as well. This bug has be

CVE-2025-1278
GitLab DevOps
5.3
MEDIUM
EPSS
0.1%
2025 CWE-1220 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

CVE-2023-4002
GitLab DevOps
5.3
MEDIUM
EPSS
0.1%
2023 CWE-201 2 PoCs

An issue has been discovered in GitLab EE affecting all versions starting from 14.1 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for EE-licensed users to link any security policy project by its ID to projects or groups the user has access to, potentially revealing the security projects's configured security policies.

CVE-2020-26413
GitLab CE/EE DevOps ⚡ nuclei
5.3
MEDIUM
EPSS
82.1%
2020 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.

CVE-2023-31416
Elastic Cloud on Kubernetes DevOps Cloud
5.3
MEDIUM
EPSS
0.2%
2023 CWE-200 1 PoC

Secret token configuration is never applied when using ECK <2.8 with APM Server >=8.0. This could lead to anonymous requests to an APM Server being accepted and the data ingested into this APM deployment.

CVE-2025-13472
BlazeMeter DevOps
5.3
MEDIUM
EPSS
0.0%
2025 CWE-862 1 PoC

A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like credential IDs, bzm workspaces and bzm project Ids. Prior to this fix, anyone could see this list as a dropdown on the Jenkins UI.