1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2023-1417
GitLab DevOps
4.3
MEDIUM
EPSS
0.6%
2023 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible for an unauthorised user to add child epics linked to victim's epic in an unrelated group.

CVE-2021-39884
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2021 1 PoC

In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.

CVE-2024-0861
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2024 CWE-425 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the `Guest` role can change `Custom dashboard projects` settings contrary to permissions.

CVE-2021-39868
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2021 1 PoC

In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project with unlimited repository size by modifying values in a project export.

CVE-2023-3964
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public projects that have package registry disabled in the project settings.

CVE-2021-39892
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2021 2 PoCs

In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users.

CVE-2018-1002100
Kubernetes DevOps
4.2
MEDIUM
EPSS
0.5%
2018 1 PoC

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

CVE-2020-13294
GitLab DevOps
4.2
MEDIUM
EPSS
0.3%
2020 1 PoC

In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.

CVE-2019-3828
Ansible DevOps
4.2
MEDIUM
EPSS
0.0%
2019 CWE-22 1 PoC

Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.

CVE-2025-6197
Grafana DevOps ⚡ nuclei
4.2
MEDIUM
EPSS
0.6%
2025 CWE-601 0 PoCs

An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL

CVE-2026-1230
GitLab DevOps
4.1
MEDIUM
EPSS
0.1%
2026 CWE-706 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due to incorrect validation of branch references under certain circumstances.

CVE-2024-0134
NVIDIA Container Toolkit DevOps
4.1
MEDIUM
EPSS
0.2%
2024 CWE-61 1 PoC

NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.

CVE-2024-5318
GitLab DevOps
4.0
MEDIUM
EPSS
0.0%
2024 CWE-862 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and starting from 17.0 prior to 17.0.1. A Guest user can view dependency lists of private projects through job artifacts.

CVE-2020-13304
GitLab DevOps
3.8
LOW
EPSS
0.3%
2020 1 PoC

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions.

CVE-2020-2023
Kata Containers DevOps
3.8
LOW
EPSS
1.8%
2020 CWE-250 1 PoC

Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; and Kata Containers 1.9 and earlier versions.

CVE-2023-3509
GitLab DevOps
3.7
LOW
EPSS
0.0%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible deploy keys associated with projects in the group.

CVE-2020-13315
GitLab DevOps
3.7
LOW
EPSS
0.4%
2020 1 PoC

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a denial of service.

CVE-2025-14592
GitLab DevOps Web
3.7
LOW
EPSS
0.0%
2025 CWE-862 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized operations by submitting GraphQL mutations through the GLQL API endpoint.

CVE-2024-9773
GitLab DevOps
3.7
LOW
EPSS
0.0%
2024 CWE-77 1 PoC

An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI.

CVE-2022-0489
GitLab DevOps
3.5
LOW
EPSS
0.2%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.