106 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2022-2250
GitLab DevOps
4.7
MEDIUM
EPSS
0.3%
2022 1 PoC

An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVE-2022-3486
GitLab DevOps
4.7
MEDIUM
EPSS
0.4%
2022 2 PoCs

An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2, allows an attacker to redirect users to an arbitrary location if they trust the URL.

CVE-2022-3205
Red Hat Ansible Automation Platform 1.2 DevOps Web
4.6
MEDIUM
EPSS
0.5%
2022 CWE-79 1 PoC

Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS injection

CVE-2022-1174
GitLab DevOps
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to trigger high CPU usage via a special crafted input added in Issues, Merge requests, Milestones, Snippets, Wiki pages, etc.

CVE-2022-0125
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was not verifying that a maintainer of a project had the right access to import members from a target project.

CVE-2022-1417
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via malicious CI jobs

CVE-2022-0373
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-members to retrieve the service desk email address

CVE-2022-1416
GitLab DevOps
4.3
MEDIUM
EPSS
0.2%
2022 1 PoC

Missing sanitization of data in Pipeline error messages in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows for rendering of attacker controlled HTML tags and CSS styling

CVE-2022-1193
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2022 1 PoC

Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances

CVE-2022-3514
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex issue in the submodule URL parser.

CVE-2022-3030
GitLab DevOps
4.3
MEDIUM
EPSS
0.3%
2022 1 PoC

An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of pipeline status to unauthorized users.

CVE-2022-3812
Bento4 DevOps
4.3
MEDIUM
EPSS
0.3%
2022 CWE-404 1 PoC

A vulnerability was found in Axiomatic Bento4. It has been rated as problematic. Affected by this issue is the function AP4_ContainerAtom::AP4_ContainerAtom of the component mp4encrypt. The manipulation leads to memory leak. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-212678 is the identifier assigned to this vulnerability.

CVE-2022-4335
GitLab DevOps
4.3
MEDIUM
EPSS
0.4%
2022 1 PoC

A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.

CVE-2022-3288
GitLab DevOps
3.5
LOW
EPSS
0.1%
2022 1 PoC

A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.

CVE-2022-0489
GitLab DevOps
3.5
LOW
EPSS
0.2%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

CVE-2022-4201
GitLab DevOps
3.5
LOW
EPSS
0.1%
2022 1 PoC

A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner.

CVE-2022-2227
GitLab DevOps Web
3.1
LOW
EPSS
0.2%
2022 1 PoC

Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows a previous maintainer of a project with a specific runner to access job and project meta data under certain conditions

CVE-2022-0740
GitLab DevOps
3.1
LOW
EPSS
0.1%
2022 1 PoC

Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana tasks from unrestricted branches.

CVE-2022-24331
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2022 2 PoCs

In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.

CVE-2022-1436
WPCargo Track & Trace DevOps Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-79 1 PoC

The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number parameter before outputting it back in the page, which could allow attackers to perform reflected Cross-Site Scripting attacks.