131 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2020-35561
Software Genérico DevOps
5.3
MEDIUM
EPSS
0.8%
2020 1 PoC

An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allowing an unauthenticated attacker to scan for open ports.

CVE-2020-7693
sockjs DevOps
5.3
MEDIUM
EPSS
16.0%
2020 2 PoCs

Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.

CVE-2020-14330
Ansible DevOps
5.0
MEDIUM
EPSS
0.2%
2020 CWE-532 1 PoC

An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an attacker to access the logs or outputs of performed tasks to read keys used in playbooks from other users within the uri module. The highest threat from this vulnerability is to data confidentiality.

CVE-2020-10685
Ansible DevOps Cloud
5.0
MEDIUM
EPSS
0.2%
2020 CWE-459 1 PoC

A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts vault files such as assemble, script, unarchive, win_copy, aws_s3 or copy modules. The temporary directory is created in /tmp leaves the s ts unencrypted. On Operating Systems which /tmp is not a tmpfs but part of the root partition, the directory is only cleared on boot and the decryp emains when the host is switched off. The system will be vulne

CVE-2020-1753
Ansible DevOps
5.0
MEDIUM
EPSS
0.1%
2020 CWE-200 2 PoCs

A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are passed to kubectl from the command line, not using an environment variable or an input configuration file. This will disclose passwords and tokens from process list and no_log directive from debug module would not have any effect making these secrets being disclosed on stdout and log files.

CVE-2020-10744
ansible DevOps
5.0
MEDIUM
EPSS
0.0%
2020 CWE-377 1 PoC

An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directive. The provided fix is insufficient to prevent the race condition on systems using ACLs and FUSE filesystems. Ansible Engine 2.7.18, 2.8.12, and 2.9.9 as well as previous versions are affected and Ansible Tower 3.4.5, 3.5.6 and 3.6.4 as well as previous versions are affected.

CVE-2020-8565
Kubernetes DevOps Web
4.7
MEDIUM
EPSS
0.1%
2020 CWE-532 1 PoC

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

CVE-2020-8563
Kubernetes DevOps Cloud
4.7
MEDIUM
EPSS
0.1%
2020 CWE-532 1 PoC

In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.

CVE-2020-13330
GitLab DevOps Web
4.4
MEDIUM
EPSS
0.1%
2020 1 PoC

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in import the Bitbucket project feature.

CVE-2020-13311
GitLab DevOps
4.3
MEDIUM
EPSS
0.2%
2020 1 PoC

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Wiki was vulnerable to a parser attack that prohibits anyone from accessing the Wiki functionality through the user interface.

CVE-2020-13265
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2020 1 PoC

User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification

CVE-2020-35568
Software Genérico DevOps
4.3
MEDIUM
EPSS
0.3%
2020 1 PoC

An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An incomplete filter applied to a database response allows an authenticated attacker to gain non-public information about other users and devices in the account.

CVE-2020-8551
Kubernetes DevOps Web
4.3
MEDIUM
EPSS
0.6%
2020 CWE-789 1 PoC

The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250.

CVE-2020-13335
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2020 1 PoC

Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.

CVE-2020-8569
CSI Snapshotter DevOps
4.3
MEDIUM
EPSS
0.3%
2020 CWE-476 1 PoC

Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, is automatically restarted by Kubernetes, and processes the same VolumeSnapshot custom resource after the restart, entering an endless crashloop. Only the volume snapshot feature is affected by this vulnerability. When exploited, users can’t take snapshots of their volumes or delete the snapshots. Al

CVE-2020-26409
GitLab CE/EE DevOps
4.3
MEDIUM
EPSS
0.2%
2020 1 PoC

A DOS vulnerability exists in Gitlab CE/EE >=10.3, <13.4.7,>=13.5, <13.5.5,>=13.6, <13.6.2 that allows an attacker to trigger uncontrolled resource by bypassing input validation in markdown fields.

CVE-2020-13294
GitLab DevOps
4.2
MEDIUM
EPSS
0.3%
2020 1 PoC

In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.

CVE-2020-13304
GitLab DevOps
3.8
LOW
EPSS
0.3%
2020 1 PoC

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Same 2 factor Authentication secret code was generated which resulted an attacker to maintain access under certain conditions.

CVE-2020-2023
Kata Containers DevOps
3.8
LOW
EPSS
1.8%
2020 CWE-250 1 PoC

Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than 1.10.5; and Kata Containers 1.9 and earlier versions.

CVE-2020-13315
GitLab DevOps
3.7
LOW
EPSS
0.4%
2020 1 PoC

A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a denial of service.