131 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2020-13282
GitLab DevOps
3.1
LOW
EPSS
0.1%
2020 1 PoC

For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.

CVE-2020-13350
GitLab CE/EE DevOps Web
3.1
LOW
EPSS
0.2%
2020 1 PoC

CSRF in runner administration page in all versions of GitLab CE/EE allows an attacker who's able to target GitLab instance administrators to pause/resume runners. Affected versions are >=13.5.0, <13.5.2,>=13.4.0, <13.4.5,<13.3.9.

CVE-2020-2103
Jenkins DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
45.2%
2020 0 PoCs

Jenkins 2.218 and earlier, LTS 2.204.1 and earlier exposed session identifiers on a user's detail object in the whoAmI diagnostic page.

CVE-2020-2231
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.

CVE-2020-2094
Jenkins Health Advisor by CloudBees Plugin DevOps Cloud
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

A missing permission check in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers with Overall/Read permission to send a fixed email to an attacker-specific recipient.

CVE-2020-12052
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVE-2020-2230
Jenkins DevOps Web
N/A
UNKNOWN
EPSS
0.4%
2020 2 PoCs

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.

CVE-2020-13449
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.

CVE-2020-9757
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
94.3%
2020 0 PoCs

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.

CVE-2020-16248
Software Genérico DevOps ⚡ nuclei
N/A
UNKNOWN
EPSS
3.6%
2020 0 PoCs

Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted as both intended functionality and also a vulnerability

CVE-2020-11492
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
5.6%
2020 4 PoCs

An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker can intercept a connection attempt from Docker Service (which runs as SYSTEM), and then impersonate their privileges.

CVE-2020-8826
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

As of v1.5.0, the Argo web interface authentication system issued immutable tokens. Authentication tokens, once issued, were usable forever without expiration—there was no refresh or forced re-authentication.

CVE-2020-25055
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unprivileged SecureFolder process) to bypass admin restrictions in KnoxContainer. The Samsung ID is SVE-2020-18133 (August 2020).

CVE-2020-13401
Software Genérico DevOps Networking
N/A
UNKNOWN
EPSS
12.9%
2020 1 PoC

An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.

CVE-2020-24815
Software Genérico DevOps
N/A
UNKNOWN
EPSS
7.5%
2020 1 PoC

A Server-Side Request Forgery (SSRF) affecting the PDF generation in MicroStrategy 10.4, 2019 before Update 6, and 2020 before Update 2 allows authenticated users to access the content of internal network resources or leak files from the local system via HTML containers embedded in a dossier/dashboard document. NOTE: 10.4., no fix will be released as version will reach end-of-life on 31/12/2020.

CVE-2020-7606
docker-compose-remote-api DevOps Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

docker-compose-remote-api through 0.1.4 allows execution of arbitrary commands. Within 'index.js' of the package, the function 'exec(serviceName, cmd, fnStdout, fnStderr, fnExit)' uses the variable 'serviceName' which can be controlled by users without any sanitization.

CVE-2020-3670
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables DevOps
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

u'Potential out of bounds read while processing downlink NAS transport message due to improper length check of Information Element(IEI) NAS message container' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in Agatti, APQ8053, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909W, MSM8917, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCM2150, QCM6125, QCS605, QCS610, QM215, Rennell, SA415M, Saipan, SC7180, SC8180X, SDA660, SDA845, SDM4

CVE-2020-25040
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.

CVE-2020-15360
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2020 2 PoCs

com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.

CVE-2020-7010
Elastic Cloud on Kubernetes DevOps Database Cloud
N/A
UNKNOWN
EPSS
0.4%
2020 CWE-335 1 PoC

Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the Elasticsearch credentials generated by ECK.