1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2019-1003005
Jenkins Script Security Plugin DevOps Web
N/A
UNKNOWN
EPSS
74.2%
2019 1 PoC

A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/SecureGroovyScript.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.

CVE-2019-6787
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The GitLab API allowed project Maintainers and Owners to view the trigger tokens of other project users.

CVE-2020-11576
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Fixed in v1.5.1, Argo version v1.5.0 was vulnerable to a user-enumeration vulnerability which allowed attackers to determine the usernames of valid (non-SSO) accounts because /api/v1/session returned 401 for an existing username and 404 otherwise.

CVE-2019-15575
GitLab CE/EE DevOps Web
N/A
UNKNOWN
EPSS
2.7%
2019 CWE-77 1 PoC

A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.

CVE-2020-2152
Jenkins Subversion Release Manager Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.

CVE-2020-13379
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2020 4 PoCs

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

CVE-2019-15419
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Asus ASUS_X015_1 Android device with a build fingerprint of asus/CN_X015/ASUS_X015_1:7.0/NRD90M/CN_X015-14.00.1709.35-20171215:user/release-keys contains a pre-installed app with a package name of com.lovelyfont.defcontainer app (versionCode=5, versionName=5.0.1) that allows unauthorized command execution via a confused deputy attack. This capability can be accessed by any app co-located on the device.

CVE-2019-10321
Jenkins Artifactory Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVE-2016-5488
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
1.2%
2016 1 PoC

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.3.0 allows remote attackers to affect availability via vectors related to Web Container, a different vulnerability than CVE-2016-3445.

CVE-2015-3630
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.

CVE-2016-4997
Software Genérico DevOps
N/A
UNKNOWN
EPSS
4.8%
2016 5 PoCs

The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.

CVE-2019-15417
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Tecno Spark Pro Android device with a build fingerprint of TECNO/H3722/TECNO-K8:7.0/NRD90M/K8-H3722ABCDE-N-171229V96:user/release-keys contains a pre-installed app with a package name of com.lovelyfont.defcontainer app (versionCode=7, versionName=7.0.5) that allows unauthorized dynamic code loading via a confused deputy attack. This capability can be accessed by any app co-located on the device.

CVE-2016-5059
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 DevOps
N/A
UNKNOWN
EPSS
0.2%
2016 1 PoC

OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screenshots under /private/var/mobile/Containers/Data/Application.

CVE-2016-3727
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2016 1 PoC

The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.

CVE-2016-3499
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
7.4%
2016 2 PoCs

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.3.0 and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Web Container.

CVE-2016-5051
OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 DevOps
N/A
UNKNOWN
EPSS
0.5%
2016 1 PoC

OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data/Application.

CVE-2016-5817
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.3%
2016 1 PoC

SQL injection vulnerability in news pages in Cargotec Navis WebAccess before 2016-08-10 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2019-16097
Software Genérico DevOps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2019 6 PoCs

core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is setup with DB as authentication backend and allow user to do self-registration. Fixed version: v1.7.6 v1.8.3. v.1.9.0. Workaround without applying the fix: configure Harbor to use non-DB authentication backend such as LDAP.

CVE-2016-3726
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2016 1 PoC

Multiple open redirect vulnerabilities in Jenkins before 2.3 and LTS before 1.651.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors related to "scheme-relative" URLs.

CVE-2019-6995
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Users are able to comment on locked project issues.