1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2016-7569
Software Genérico DevOps
N/A
UNKNOWN
EPSS
1.2%
2016 2 PoCs

Directory traversal vulnerability in docker2aci before 0.13.0 allows remote attackers to write to arbitrary files via a .. (dot dot) in the embedded layer data in an image.

CVE-2016-9086
Software Genérico DevOps
N/A
UNKNOWN
EPSS
13.5%
2016 1 PoC

GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab servic

CVE-2016-4340
Software Genérico DevOps
N/A
UNKNOWN
EPSS
2.5%
2016 2 PoCs

The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.

CVE-2016-4998
Software Genérico DevOps
N/A
UNKNOWN
EPSS
1.6%
2016 3 PoCs

The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel before 4.6 allows local users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from kernel heap memory by leveraging in-container root access to provide a crafted offset value that leads to crossing a ruleset blob boundary.

CVE-2019-5469
GitLab DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 CWE-639 1 PoC

An IDOR vulnerability exists in GitLab <v12.1.2, <v12.0.4, and <v11.11.6 that allowed uploading files from project archive to replace other users files potentially allowing an attacker to replace project binaries or other uploaded assets.

CVE-2016-3724
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2016 1 PoC

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.

CVE-2016-3445
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
1.5%
2016 2 PoCs

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.3.0 allows remote attackers to affect availability via vectors related to Web Container, a different vulnerability than CVE-2016-5488.

CVE-2019-15341
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

The Tecno Camon iAir 2 Plus Android device with a build fingerprint of TECNO/H622/TECNO-ID3k:8.1.0/O11019/E-180914V83:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.0.11). This app contains an exported service named com.lovelyfont.manager.service.FunctionService that allows any app co-located on the device to supply the file path to a Dalvik Executable (DEX) file which it will dynamically load within its own process and execute in with its own system privileges. This app cannot be disabled by the user and

CVE-2016-3607
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
4.6%
2016 3 PoCs

Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Web Container.

CVE-2013-0327
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2013 1 PoC

Cross-site request forgery (CSRF) vulnerability in Jenkins master in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to hijack the authentication of users via unknown vectors.

CVE-2015-1318
Software Genérico DevOps
N/A
UNKNOWN
EPSS
19.1%
2015 4 PoCs

The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport file in a namespace (container).

CVE-2016-6150
Software Genérico DevOps
N/A
UNKNOWN
EPSS
1.8%
2016 1 PoC

The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended access restrictions and possibly have unspecified other impact via unknown vectors, aka SAP Security Note 2233550.

CVE-2019-19922
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 3 PoCs

kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration would typically be seen with benign workloads, it is possible that an attacker could calculate how many stray requests are required to force an entire Kubernetes cluster into a low-performance state caused by slice expiration, and ensure that a DDoS attack sent that number

CVE-2016-3722
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2016 1 PoC

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the "full name."

CVE-2016-0792
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
90.9%
2016 6 PoCs

Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.

CVE-2019-5486
GitLab CE/EE DevOps
N/A
UNKNOWN
EPSS
0.0%
2019 CWE-288 1 PoC

A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

CVE-2016-1682
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.7%
2016 1 PoC

The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a ServiceWorker registration.

CVE-2016-2166
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2016 1 PoC

The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might allow man-in-the-middle attackers to obtain sensitive information or modify data via unspecified vectors.

CVE-2019-15725
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.5%
2019 2 PoCs

An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other information.

CVE-2016-3723
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2016 1 PoC

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.