88 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2024-23055
Software Genérico DevOps ⚡ nuclei
6.1
MEDIUM
EPSS
4.0%
2024 1 PoC

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.

CVE-2024-31204
mailcow-dockerized DevOps Web
6.1
MEDIUM
EPSS
4.6%
2024 CWE-79 1 PoC

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This vulnerability resides in the exception handling mechanism, specifically when not operating in DEV_MODE. The system saves exception details into a session array without proper sanitization or encoding. These details are later rendered into HTML and executed in a JavaScript block within the user's browser, without adequate escaping of HTML entities. This flaw allows for Cross-Site Scripting (XSS) attacks, where attackers ca

CVE-2024-23995
Software Genérico DevOps Web
6.1
MEDIUM
EPSS
1.5%
2024 2 PoCs

Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in the column name of a database table in tabulator-popup-container.

CVE-2024-6502
GitLab DevOps
5.7
MEDIUM
EPSS
0.1%
2024 CWE-684 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from 17.3 prior to 17.3.1, which allows an attacker to create a branch with the same name as a deleted tag.

CVE-2024-8631
GitLab DevOps
5.5
MEDIUM
EPSS
0.0%
2024 CWE-267 1 PoC

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.

CVE-2024-41968
CC100 0751-9x01 DevOps
5.4
MEDIUM
EPSS
0.6%
2024 CWE-306 1 PoC

A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.

CVE-2024-8647
GitLab DevOps Web
5.4
MEDIUM
EPSS
0.2%
2024 CWE-22 1 PoC

An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.

CVE-2024-37152
argo-cd DevOps Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
80.2%
2024 CWE-287 0 PoCs

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without authentication. All sensitive settings are hidden except passwordPattern. This vulnerability is fixed in 2.11.3, 2.10.12, and 2.9.17.

CVE-2024-2191
GitLab DevOps
5.3
MEDIUM
EPSS
0.2%
2024 CWE-284 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

CVE-2024-8650
GitLab DevOps
5.3
MEDIUM
EPSS
0.2%
2024 CWE-863 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

CVE-2024-8118
Grafana DevOps Web
5.1
MEDIUM
EPSS
0.1%
2024 CWE-653 1 PoC

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

CVE-2024-5257
GitLab DevOps
4.9
MEDIUM
EPSS
0.0%
2024 CWE-284 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Developer user with `admin_compliance_framework` custom role may have been able to modify the URL for a group namespace.

CVE-2024-41453
Software Genérico DevOps Web
4.8
MEDIUM
EPSS
0.9%
2024 2 PoCs

A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.

CVE-2024-40635
containerd DevOps
4.6
MEDIUM
EPSS
0.1%
2024 CWE-190 1 PoC

containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This could cause unexpected behavior for environments that require containers to run as a non-root user. This bug has been fixed in containerd 1.6.38, 1.7.27, and 2.04. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

CVE-2024-8266
GitLab DevOps
4.4
MEDIUM
EPSS
0.1%
2024 CWE-250 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.

CVE-2024-4201
GitLab DevOps Web
4.4
MEDIUM
EPSS
1.1%
2024 CWE-79 1 PoC

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.

CVE-2024-9367
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2024 CWE-770 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.

CVE-2024-12244
GitLab DevOps
4.3
MEDIUM
EPSS
0.1%
2024 CWE-862 1 PoC

An issue has been discovered in access controls could allow users to view certain restricted project information even when related features are disabled in GitLab EE, affecting all versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1.

CVE-2024-3127
GitLab DevOps
4.3
MEDIUM
EPSS
0.0%
2024 CWE-284 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions starting from 17.3 before 17.3.1. Under certain conditions it may be possible to bypass the IP restriction for groups through GraphQL allowing unauthorised users to perform some actions at the group level.

CVE-2024-3825
BlazeMeter Jenkins plugin DevOps
4.3
MEDIUM
EPSS
0.2%
2024 CWE-352 1 PoC

Versions of the BlazeMeter Jenkins plugin prior to 4.22 contain a flaw which results in credential enumeration