157 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2019-15737
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improved authentication and session management.

CVE-2019-2856
WebLogic Server DevOps Database
N/A
UNKNOWN
EPSS
1.8%
2019 1 PoC

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Application Container - JavaEE). Supported versions that are affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2019-15730
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a SSRF vulnerability as a result of a bypass of the current protection mechanisms against this type of attack, which would allow sending requests to any resources accessible in the local network by the GitLab server.

CVE-2019-15728
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks on the Kubernetes integration are insufficient, which could have allowed an attacker to request any local network resource accessible from the GitLab server.

CVE-2019-6996
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. The merge request approvers section has an access control issue that permits project maintainers to view membership of private groups.

CVE-2019-10322
Jenkins Artifactory Plugin DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

CVE-2019-13068
Software Genérico DevOps
N/A
UNKNOWN
EPSS
5.0%
2019 1 PoC

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

CVE-2019-5487
GitLab EE DevOps Database
N/A
UNKNOWN
EPSS
0.3%
2019 CWE-284 1 PoC

An improper access control vulnerability exists in Gitlab EE <v12.3.3, <v12.2.7, & <v12.1.13 that allowed the group search feature with Elasticsearch to return private code, merge requests and commits.

CVE-2019-14271
Software Genérico DevOps
N/A
UNKNOWN
EPSS
71.9%
2019 2 PoCs

In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.

CVE-2019-5463
GitLab CE/EE DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-200 1 PoC

An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVE-2019-0555
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
1.5%
2019 1 PoC

An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft XmlDocument Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows Server 2019, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.

CVE-2019-15726
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in markdown could be pointed to an arbitrary server, which would reveal the IP address of clients requesting the file from that server.

CVE-2019-9172
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 2 of 5).

CVE-2019-7176
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 8.x (starting in 8.9), 9.x, 10.x, and 11.x before 11.5.9, 11.6.x before 11.6.7, and 11.7.x before 11.7.2. It has Incorrect Access Control. Guest users are able to add reaction emojis on comments to which they have no visibility.

CVE-2019-15729
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.5%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran for a merge request.

CVE-2019-6790
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2019 1 PoC

An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and later but before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. Guest users were able to view the list of a group's merge requests.

CVE-2019-15722
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources.

CVE-2019-10384
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.

CVE-2019-1010241
Jenkins DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-257 1 PoC

Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly line #30 (passwordVariable). The attack vector is: Attacker creates and executes a Jenkins job.

CVE-2019-13004
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. When specific encoded characters were added to comments, the comments section would become inaccessible. It has Incorrect Access Control (issue 1 of 2).