1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2020-12052
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVE-2019-6788
Software Genérico DevOps
N/A
UNKNOWN
EPSS
20.2%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 3 of 6). For installations using GitHub or Bitbucket OAuth integrations, it is possible to use a covert redirect to obtain the user OAuth token for those services.

CVE-2020-11492
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
5.6%
2020 4 PoCs

An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker can intercept a connection attempt from Docker Service (which runs as SYSTEM), and then impersonate their privileges.

CVE-2013-2034
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2013 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary code or (2) initiate deployment of binaries to a Maven repository via unspecified vectors.

CVE-2015-5305
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2015 1 PoC

Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly handled before passing it to etcd.

CVE-2020-13401
Software Genérico DevOps Networking
N/A
UNKNOWN
EPSS
12.9%
2020 1 PoC

An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.

CVE-2019-6794
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6). A project guest user can view the last commit status of the default branch.

CVE-2020-14370
podman DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-212 1 PoC

An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.

CVE-2019-15738
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge request IDs were being disclosed via email.

CVE-2019-15591
GitLab DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-284 1 PoC

An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.

CVE-2019-15344
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The Tecno Camon iClick Android device with a build fingerprint of TECNO/H633/TECNO-IN6:8.1.0/O11019/A-180409V96:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.8). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. In addition to the local attack surface, its accompany

CVE-2019-15740
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 7.9 through 12.2.1. EXIF Geolocation data was not being removed from certain image uploads.

CVE-2020-10665
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privileges, leading to arbitrary DACL permissions overwrites and arbitrary file writes. This affects Docker Desktop Enterprise before 2.1.0.9, Docker Desktop for Windows Stable before 2.2.0.4, and Docker Desktop for Windows Edge before 2.2.2.0.

CVE-2019-10323
Jenkins Artifactory Plugin DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

A missing permission check in Jenkins Artifactory Plugin 3.2.3 and earlier in various 'fillCredentialsIdItems' methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

CVE-2020-10697
Tower DevOps
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-862 1 PoC

A flaw was found in Ansible Tower when running Openshift. Tower runs a memcached, which is accessed via TCP. An attacker can take advantage of writing a playbook polluting this cache, causing a denial of service attack. This attack would not completely stop the service, but in the worst-case scenario, it can reduce the Tower performance, for which memcached is designed. Theoretically, more sophisticated attacks can be performed by manipulating and crafting the cache, as Tower relies on memcached as a place to pull out setting values. Confidential and sensitive data stored in memcached should n

CVE-2019-6797
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An information disclosure issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitHub token used in CI/CD for External Repos was being leaked to project maintainers in the UI.

CVE-2015-3627
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.

CVE-2019-15388
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.1.13). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. In addition to the local attack surface, its accompa

CVE-2020-2230
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.