92 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2021-22176
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2021 1 PoC

An issue has been discovered in GitLab affecting all versions starting with 3.0.1. Improper access control allows demoted project members to access details on authored merge requests

CVE-2021-39881
GitLab DevOps
3.5
LOW
EPSS
0.3%
2021 1 PoC

In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client application with arbitrary scope names which may allow the malicious user to trick unsuspecting users to authorize the malicious client application using the spoofed scope name and description.

CVE-2021-39936
GitLab DevOps
3.5
LOW
EPSS
0.3%
2021 1 PoC

Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.

CVE-2021-32718
rabbitmq-server DevOps Web
3.1
LOW
EPSS
0.1%
2021 CWE-80 1 PoC

RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via management UI could lead to the user's bane being rendered in a confirmation message without proper `<script>` tag sanitization, potentially allowing for JavaScript code execution in the context of the page. In order for this to occur, the user must be signed in and have elevated permissions (other user management). The vulnerability is patched in RabbitMQ 3.8.17. As a workaround, disable `rabbitmq_management` plugin and use CLI tools for management operations and Prometheus an

CVE-2021-39914
GitLab DevOps
3.1
LOW
EPSS
0.2%
2021 1 PoC

A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause excessive usage of resources when a specially crafted username was used when provisioning a new user

CVE-2021-22245
GitLab DevOps
2.7
LOW
EPSS
0.4%
2021 1 PoC

Improper validation of commit author in GitLab CE/EE affecting all versions allowed an attacker to make several pages in a project impossible to view

CVE-2021-29641
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
6.6%
2021 3 PoCs

Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ability to upload a .php file to the main upload directory and/or upload a .php file and a .htaccess file to a subdirectory. Exploitation succeeds only for certain installations with the Apache HTTP Server and the local-storage driver (e.g., when the product was obtained from hub.docker.com).

CVE-2021-33923
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database).

CVE-2021-33924
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.8%
2021 2 PoCs

Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allows remote attackers to access sensitive information.

CVE-2021-21978
VMware View Planner DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
90.5%
2021 4 PoCs

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.

CVE-2021-27886
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
22.4%
2021 1 PoC

rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.

CVE-2021-20166
Netgear RAX43 DevOps Networking
N/A
UNKNOWN
EPSS
64.2%
2021 1 PoC

Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router containers a buffer overrun issue that can redirection control flow of the applicaiton.

CVE-2021-43196
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.

CVE-2021-0595
Android DevOps
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In lockAllProfileTasks of RootWindowContainer.java, there is a possible way to access the work profile without the profile PIN, after logging in. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-177457096

CVE-2021-37573
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
51.9%
2021 3 PoCs

A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS) <=1.115 allows an adversary to inject malicious code on the server's "404 Page not Found" error page

CVE-2021-4178
kubernetes-client DevOps
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-502 1 PoC

A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.

CVE-2021-37841
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full container compromise in both process isolation and Hyper-V isolation modes. This security issue leads an attacker with low privilege to read, write and possibly even execute code inside the containers.

CVE-2021-3602
buildah DevOps
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-200 1 PoC

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).

CVE-2021-27962
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

CVE-2021-25003
WPCargo Track & Trace DevOps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.6%
2021 CWE-94 2 PoCs

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE