1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2020-27151
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries given using annotations without any kind of validation. Someone who is granted access rights to a cluster will be able to have kata-runtime execute arbitrary binaries as root on the worker nodes.

CVE-2019-19311
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.

CVE-2020-8570
Kubernetes Java Client DevOps
N/A
UNKNOWN
EPSS
1.1%
2020 CWE-23 2 PoCs

Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.

CVE-2020-8945
Software Genérico DevOps
N/A
UNKNOWN
EPSS
1.9%
2020 1 PoC

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

CVE-2019-13009
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 9.2 through 12.0.2. Uploaded files associated with unsaved personal snippets were accessible to unauthorized users due to improper permission settings. It has Incorrect Access Control.

CVE-2020-2261
Jenkins Perfecto Plugin DevOps
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Configure permission to run arbitrary commands on the Jenkins controller

CVE-2019-2856
WebLogic Server DevOps Database
N/A
UNKNOWN
EPSS
1.8%
2019 1 PoC

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Application Container - JavaEE). Supported versions that are affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2020-2103
Jenkins DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
45.2%
2020 0 PoCs

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.

CVE-2015-6927
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

vzctl before 4.9.4 determines the virtual environment (VE) layout based on the presence of root.hdd/DiskDescriptor.xml in the VE private directory, which allows local simfs container (CT) root users to change the root password for arbitrary ploop containers, as demonstrated by a symlink attack on the ploop container root.hdd file and then access a control panel.

CVE-2019-15721
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintentionally allowed group maintainers to view and edit group runner settings.

CVE-2020-2231
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.

CVE-2020-2094
Jenkins Health Advisor by CloudBees Plugin DevOps Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient.

CVE-2019-6786
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control (issue 1 of 3). The contents of an LFS object can be accessed by an unauthorized user, if the file size and OID are known.

CVE-2020-13449
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.

CVE-2019-13068
Software Genérico DevOps
N/A
UNKNOWN
EPSS
5.0%
2019 1 PoC

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

CVE-2019-6960
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.

CVE-2019-14271
Software Genérico DevOps
N/A
UNKNOWN
EPSS
71.9%
2019 2 PoCs

In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.

CVE-2020-9757
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2020 0 PoCs

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.

CVE-2020-8826
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authentication.

CVE-2019-15593
GitLab DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 CWE-400 1 PoC

GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a Denial of Service attack in Issue Comments.