1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2023-31299
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode field of a container.

CVE-2019-10475
Jenkins build-metrics Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2019 2 PoCs

A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.

CVE-2019-13002
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. Unauthorized users were able to read pipeline information of the last merge request. It has Incorrect Access Control.

CVE-2019-15733
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch name could be exposed to unauthorized users.

CVE-2015-3629
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container.

CVE-2019-6996
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups.

CVE-2019-15729
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran for a merge request.

CVE-2020-16248
Software Genérico DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
3.6%
2020 0 PoCs

Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability

CVE-2020-2159
Jenkins CryptoMove Plugin DevOps
N/A
UNKNOWN
EPSS
4.5%
2020 1 PoC

Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the OS user account running Jenkins.

CVE-2019-10384
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.

CVE-2020-2322
Jenkins Chaos Monkey Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Jenkins Chaos Monkey Plugin 0.3 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to generate load and to generate memory leaks.

CVE-2019-1010241
Jenkins DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-257 1 PoC

Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly line #30 (passwordVariable). The attack vector is: Attacker creates and executes a Jenkins job.

CVE-2020-7010
Elastic Cloud on Kubernetes DevOps Database Cloud
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-335 1 PoC

Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK.

CVE-2019-15347
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Tecno Camon iClick 2 Android device with a build fingerprint of TECNO/H622/TECNO-ID6:8.1.0/O11019/F-180824V116:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands via shell script to be executed as the system user that are triggered by writing an attacker-selected message to the logcat log. This app cannot be disabled by the user and the attack

CVE-2020-2096
Jenkins Gitlab Hook Plugin DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
92.7%
2020 1 PoC

Jenkins Gitlab Hook Plugin 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected XSS vulnerability.

CVE-2019-6781
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

CVE-2020-10716
rubygem-foreman_ansible DevOps
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-285 1 PoC

A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a malicious Satellite user to scan through the Job Invocation, with the ability to search for passwords and other sensitive data. This flaw affects tfm-rubygem-foreman_ansible versions before 4.0.3.4.

CVE-2019-10109
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 2 PoCs

An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. EXIF geolocation data were not removed from images when uploaded to GitLab. As a result, anyone with access to the uploaded image could obtain its geolocation, device, and software version data (if present).

CVE-2020-7373
Software Genérico DevOps
N/A
UNKNOWN
EPSS
90.3%
2020 2 PoCs

vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is a duplicate of CVE-2020-17496. CVE-2020-17496 is the preferred CVE ID to track this vulnerability.

CVE-2019-1003050
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.9%
2019 1 PoC

The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.