1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2018-19576
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential.

CVE-2019-15734
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, commit titles and team member comments could become viewable to users who did not have permission to access these.

CVE-2018-1000193
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.8%
2018 1 PoC

A improper neutralization of control sequences vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in HudsonPrivateSecurityRealm.java that allows users to sign up using user names containing control characters that can then appear to have the same name as other users, and cannot be deleted via the UI.

CVE-2015-6240
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2015 1 PoC

The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.

CVE-2018-1000068
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2018 1 PoC

An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on a case-insensitive file system.

CVE-2019-1003000
Script Security Plugin DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
94.4%
2019 8 PoCs

A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins master JVM.

CVE-2018-1999002
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
93.4%
2018 5 PoCs

A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master has access to.

CVE-2018-18649
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
55.0%
2018 1 PoC

An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for remote code execution.

CVE-2019-11549
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.

CVE-2018-1000600
Software Genérico DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
93.5%
2018 0 PoCs

A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.1 and earlier in GitHubTokenCredentialsCreator.java that allows attackers to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVE-2019-15580
gitlab.com DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-201 1 PoC

An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head pipeline data of a public project even though pipeline visibility was restricted.

CVE-2018-19585
Software Genérico DevOps
N/A
UNKNOWN
EPSS
11.5%
2018 2 PoCs

GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

CVE-2018-14601
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.2. A Denial of Service can occur because Markdown rendering times are slow.

CVE-2018-21034
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.9%
2018 1 PoC

In Argo versions prior to v1.5.0-rc1, it was possible for authenticated Argo users to submit API calls to retrieve secrets and other manifests which were stored within git.

CVE-2018-19577
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

Gitlab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an incorrect access control vulnerability that displays to an unauthorized user the title and namespace of a confidential issue.

CVE-2021-27962
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access.

CVE-2018-1199
Spring by Pivotal DevOps Web
N/A
UNKNOWN
EPSS
0.8%
2018 1 PoC

Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses th

CVE-2018-19581
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

GitLab EE, versions 8.3 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, is vulnerable to an insecure object reference vulnerability that allows a Guest user to set the weight of an issue they create.

CVE-2018-9244
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

CVE-2018-19856
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2018 1 PoC

GitLab CE/EE before 11.3.12, 11.4.x before 11.4.10, and 11.5.x before 11.5.3 allows Directory Traversal in Templates API.