131 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2020-8559
Kubernetes DevOps Web
6.4
MEDIUM
EPSS
51.2%
2020 CWE-601 3 PoCs

The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

CVE-2020-13277
GitLab DevOps
6.3
MEDIUM
EPSS
4.6%
2020 3 PoCs

An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5

CVE-2020-8554
Kubernetes DevOps Web
6.3
MEDIUM
EPSS
24.8%
2020 CWE-283 8 PoCs

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.

CVE-2020-8555
Kubernetes DevOps
6.3
MEDIUM
EPSS
8.7%
2020 CWE-918 2 PoCs

The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback services).

CVE-2020-13267
GitLab DevOps Web
6.1
MEDIUM
EPSS
0.5%
2020 1 PoC

A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1

CVE-2020-15157
containerd DevOps Web
6.1
MEDIUM
EPSS
0.8%
2020 CWE-522 1 PoC

In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the default containerd resolver will follow that URL to attempt to download it. In v1.2.x but not 1.3.0 or later, the default containerd resolver will provide its authentication credentials if the server where the URL is located presents an HTTP 401 status code along with registry-specific

CVE-2020-13269
GitLab DevOps Web
6.1
MEDIUM
EPSS
0.5%
2020 2 PoCs

A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1

CVE-2020-13271
GitLab DevOps Web
6.1
MEDIUM
EPSS
0.3%
2020 1 PoC

A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

CVE-2020-10749
containernetworking/plugins DevOps Networking
6.0
MEDIUM
EPSS
5.2%
2020 CWE-300 1 PoC

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVE-2020-10726
dpdk DevOps
6.0
MEDIUM
EPSS
0.1%
2020 CWE-190 2 PoCs

A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.

CVE-2020-8553
ingress-nginx DevOps Web
5.9
MEDIUM
EPSS
0.5%
2020 CWE-73 1 PoC

The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.

CVE-2020-13301
GitLab DevOps Web
5.5
MEDIUM
EPSS
0.2%
2020 1 PoC

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a stored XSS on the standalone vulnerability page.

CVE-2020-8557
Kubernetes DevOps
5.5
MEDIUM
EPSS
0.1%
2020 CWE-400 2 PoCs

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when calculating ephemeral storage usage by a pod. If a pod writes a large amount of data to the /etc/hosts file, it could fill the storage space of the node and cause the node to fail.

CVE-2020-13316
GitLab DevOps
5.4
MEDIUM
EPSS
0.3%
2020 2 PoCs

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.

CVE-2020-13331
GitLab DevOps Web
5.4
MEDIUM
EPSS
0.1%
2020 1 PoC

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.

CVE-2020-13338
GitLab DevOps Web
5.4
MEDIUM
EPSS
0.1%
2020 1 PoC

An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.

CVE-2020-8558
Kubernetes DevOps
5.4
MEDIUM
EPSS
20.1%
2020 CWE-420 1 PoC

The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, but due to this defeect, could be reachable by other hosts on the same LAN as the node, or by containers running on the same node as the service.

CVE-2020-35570
Software Genérico DevOps
5.3
MEDIUM
EPSS
0.8%
2020 1 PoC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. An unauthenticated attacker is able to access files (that should have been restricted) via forceful browsing.

CVE-2020-7693
sockjs DevOps
5.3
MEDIUM
EPSS
16.0%
2020 2 PoCs

Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.

CVE-2020-26413
GitLab CE/EE DevOps ⚡ nuclei
5.3
MEDIUM
EPSS
82.1%
2020 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 13.6.2. Information disclosure via GraphQL results in user email being unexpectedly visible.