1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2023-41387
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses UIFileSharingEnabled and LSSupportsOpeningDocumentsInPlace properties. As a result, local users can obtain the same attack primitives as remote attackers by tampering with the internal database of the framework on the device.

CVE-2019-6997
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. System notes contain an access control issue that permits a guest user to view merge request titles.

CVE-2018-11982
Snapdragon Mobile, Snapdragon Wear DevOps
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

In Snapdragon (Mobile, Wear) in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 810, SD 820, SD 835, Snapdragon_High_Med_2016, a double free of ASN1 heap memory used for EUTRA CAP container occurs during UTRAN to LTE Capability inquiry procedure.

CVE-2018-12298
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.6%
2018 1 PoC

Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.

CVE-2019-5461
GitLab Community Edition DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 CWE-20 2 PoCs

An input validation problem was discovered in the GitHub service integration which could result in an attacker being able to make arbitrary POST requests in a GitLab instance's internal network. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVE-2018-17975
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via the GFM markdown API.

CVE-2018-8718
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.7%
2018 2 PoCs

Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.

CVE-2019-5464
GitLab CE/EE DevOps
N/A
UNKNOWN
EPSS
0.4%
2019 CWE-20 2 PoCs

A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.

CVE-2018-20144
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

GitLab Community and Enterprise Edition 11.x before 11.3.13, 11.4.x before 11.4.11, and 11.5.x before 11.5.4 has Incorrect Access Control.

CVE-2018-1000194
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.5%
2018 1 PoC

A path traversal vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in FilePath.java, SoloFilePathFilter.java that allows malicious agents to read and write arbitrary files on the Jenkins master, bypassing the agent-to-master security subsystem protection.

CVE-2019-15739
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.

CVE-2018-17976
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

An issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is Information Exposure via Epic change descriptions.

CVE-2018-1999001
Software Genérico DevOps
N/A
UNKNOWN
EPSS
27.3%
2018 1 PoC

A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from the Jenkins home directory. If Jenkins is started without this file present, it will revert to the legacy defaults of granting administrator access to anonymous users.

CVE-2019-5468
GitLab DevOps
N/A
UNKNOWN
EPSS
0.7%
2019 1 PoC

An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.

CVE-2018-3710
GitLab Community and Enterprise Editions DevOps
N/A
UNKNOWN
EPSS
4.2%
2018 CWE-377 1 PoC

Gitlab Community and Enterprise Editions version 10.3.3 is vulnerable to an Insecure Temporary File in the project import component resulting remote code execution.

CVE-2018-19493
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.

CVE-2018-18646
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows SSRF.

CVE-2018-15664
Software Genérico DevOps Web Windows
N/A
UNKNOWN
EPSS
7.3%
2018 1 PoC

In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do archive operations on a frozen filesystem (or from within a chroot).

CVE-2019-2576
Service Bus DevOps Web Database
N/A
UNKNOWN
EPSS
2.1%
2019 1 PoC

Vulnerability in the Oracle Service Bus component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Service Bus. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).

CVE-2018-12607
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.