1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2023-3904
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2023 CWE-1287 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

CVE-2023-2022
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-262 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

CVE-2022-3514
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in the submodule URL parser.

CVE-2016-3721
Software Genérico DevOps
4.3
MEDIUM
EPSS
0.4%
2016 1 PoC

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

CVE-2023-21419
Samsung Mobile Devices DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-287 1 PoC

An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition.

CVE-2020-13335
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2020 1 PoC

Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.

CVE-2023-3917
GitLab DevOps
4.3
MEDIUM
EPSS
0.2%
2023 CWE-1287 1 PoC

Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.

CVE-2020-35568
Software Genérico DevOps
4.3
MEDIUM
EPSS
0.3%
2020 1 PoC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An incomplete filter applied to a database response allows an authenticated attacker to gain non-public information about other users and devices in the account.

CVE-2020-8569
CSI Snapshotter DevOps
4.3
MEDIUM
EPSS
0.3%
2020 CWE-476 1 PoC

Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, is automatically restarted by Kubernetes, and processes the same VolumeSnapshot custom resource after the restart, entering an endless crashloop. Only the volume snapshot feature is affected by this vulnerability. When exploited, users can’t take snapshots of their volumes or delete the snapshots. Al

CVE-2023-4532
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. Users were capable of linking CI/CD jobs of private projects which they are not a member of.

CVE-2020-13311
GitLab DevOps
4.3
MEDIUM
EPSS
0.2%
2020 1 PoC

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.

CVE-2023-3920
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 11.2 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that a maintainer to create a fork relationship between existing projects contrary to the documentation.

CVE-2020-8551
Kubernetes DevOps Web
4.3
MEDIUM
EPSS
0.6%
2020 CWE-789 1 PoC

The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250.

CVE-2023-4018
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-425 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to create model experiments in public projects.

CVE-2020-13265
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2020 1 PoC

User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

CVE-2020-26409
GitLab CE/EE DevOps
4.3
MEDIUM
EPSS
0.2%
2020 1 PoC

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

CVE-2023-3900
GitLab DevOps
4.3
MEDIUM
EPSS
0.2%
2023 CWE-1287 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.

CVE-2019-6744
Knox DevOps Cloud
4.3
MEDIUM
EPSS
0.1%
2019 CWE-284 1 PoC

This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the device in order to exploit this vulnerability. The specific flaws exists within the the handling of the lock screen for Secure Folder. The issue results from the lack of proper validation that a user has correctly authenticated. An attacker can leverage this vulnerability to disclose the contents of the secure container. Was ZDI-CAN-7381.

CVE-2025-7000
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2025 CWE-201 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.

CVE-2025-2615
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2025 CWE-201 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.