1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2022-25173
Jenkins Pipeline: Groovy Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

CVE-2022-20615
Jenkins Matrix Project Plugin DevOps Web
N/A
UNKNOWN
EPSS
2.9%
2022 1 PoC

Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

CVE-2021-29641
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
6.6%
2021 3 PoCs

Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions include the ability to upload a .php file to the main upload directory and/or upload a .php file and a .htaccess file to a subdirectory. Exploitation succeeds only for certain installations with the Apache HTTP Server and the local-storage driver (e.g., when the product was obtained from hub.docker.com).

CVE-2022-20613
Jenkins Mailer Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

CVE-2021-21978
VMware View Planner DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
90.5%
2021 4 PoCs

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.

CVE-2022-43403
Jenkins Script Security Plugin DevOps
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin 1183.v774b_0b_0a_a_451 and earlier allows attackers with permission to define and run sandboxed scripts, including Pipelines, to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.

CVE-2022-0811
CRI-O DevOps
N/A
UNKNOWN
EPSS
23.8%
2022 CWE-94 1 PoC

A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the malicious pod was deployed.

CVE-2013-0328
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.1%
2013 1 PoC

Cross-site scripting (XSS) vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2021-43196
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.

CVE-2022-2990
buildah DevOps
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-842 1 PoC

An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.

CVE-2023-40345
Jenkins Delphix Plugin DevOps
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission to access and capture credentials they are not entitled to.

CVE-2021-37841
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full container compromise in both process isolation and Hyper-V isolation modes. This security issue leads an attacker with low privilege to read, write and possibly even execute code inside the containers.

CVE-2022-32532
Apache Shiro DevOps Web
N/A
UNKNOWN
EPSS
80.9%
2022 CWE-863 3 PoCs

Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.

CVE-2022-23774
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.

CVE-2022-39850
Samsung Mobile Devices DevOps
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.

CVE-2021-3602
buildah DevOps
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-200 1 PoC

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).

CVE-2021-25003
WPCargo Track & Trace DevOps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.6%
2021 CWE-94 2 PoCs

The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

CVE-2021-28147
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.5%
2021 2 PoCs

The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external groups to any existing team. This can be used to grant a user team permissions that the user isn't supposed to have.

CVE-2022-25174
Jenkins Pipeline: Shared Groovy Libraries Plugin DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

CVE-2014-0413
Software Genérico DevOps Web Database
N/A
UNKNOWN
EPSS
0.4%
2014 1 PoC

Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect integrity via vectors related to HTTP Request Handling, a different vulnerability than CVE-2014-0426.