1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2019-9220
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption.

CVE-2020-2229
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
2.6%
2020 2 PoCs

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.

CVE-2019-15577
GitLab CE/EE DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 CWE-200 1 PoC

An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.

CVE-2019-15351
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Tecno Camon Android device with a build fingerprint of TECNO/H622/TECNO-ID5b:8.1.0/O11019/G-180829V31:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands via shell script to be executed as the system user that are triggered by writing an attacker-selected message to the logcat log. This app cannot be disabled by the user and the attack can be p

CVE-2020-13936
Apache Velocity Engine DevOps Web
N/A
UNKNOWN
EPSS
16.4%
2020 2 PoCs

An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.

CVE-2019-10352
Jenkins DevOps
N/A
UNKNOWN
EPSS
40.0%
2019 1 PoC

A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.

CVE-2020-11454
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Microstrategy Web 10.4 is vulnerable to Stored XSS in the HTML Container and Insert Text features in the window, allowing for the creation of a new dashboard. In order to exploit this vulnerability, a user needs to get access to a shared dashboard or have the ability to create a dashboard on the application.

CVE-2020-13788
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.

CVE-2019-15589
GitLab CE/EE DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 CWE-284 1 PoC

An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.

CVE-2020-10709
Tower DevOps
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-287 1 PoC

A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an attacker to obtain a refresh token that does not expire. The original token granted to the user still has access to Ansible Tower, which allows any user that can gain access to the token to be fully authenticated to Ansible Tower. This flaw affects Ansible Tower versions before 3.6.4 and Ansible Tower versions before 3.5.6.

CVE-2019-10405
Jenkins DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
79.8%
2019 0 PoCs

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier printed the value of the "Cookie" HTTP request header on the /whoAmI/ URL, allowing attackers exploiting another XSS vulnerability to obtain the HTTP session cookie despite it being marked HttpOnly.

CVE-2020-2091
Jenkins Amazon EC2 Plugin DevOps Cloud
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained through another method.

CVE-2019-15389
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.4%
2019 1 PoC

The Haier A6 Android device with a build fingerprint of Haier/A6/A6:8.1.0/O11019/1534219877:userdebug/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.1.13). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. In addition to the local attack surface, its accompanying app with a

CVE-2007-5521
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.8%
2007 1 PoC

Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.2, and 10.1.3.3, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS06.

CVE-2007-6329
Software Genérico DevOps
N/A
UNKNOWN
EPSS
24.2%
2007 1 PoC

Microsoft Office 2007 12.0.6015.5000 and MSO 12.0.6017.5000 do not sign the metadata of Office Open XML (OOXML) documents, which makes it easier for remote attackers to modify Dublin Core metadata fields, as demonstrated by the (1) LastModifiedBy and (2) creator fields in docProps/core.xml in the OOXML ZIP container.

CVE-2014-8179
Docker Engine DevOps
N/A
UNKNOWN
EPSS
1.6%
2014 1 PoC

Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and bypass pull-by-digest validation.

CVE-2013-0329
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2013 1 PoC

Unspecified vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to bypass the CSRF protection mechanism via unknown attack vectors.

CVE-2015-1335
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.

CVE-2019-15724
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 2 PoCs

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.

CVE-2020-8827
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

As of v1.5.0, the Argo API does not implement anti-automation measures such as rate limiting, account lockouts, or other anti-bruteforce measures. Attackers can submit an unlimited number of authentication attempts without consequence.