113 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2023-4658
GitLab DevOps
3.1
LOW
EPSS
0.1%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

CVE-2023-4777
Container Scanning Connector Jenkins Plugin DevOps
3.1
LOW
EPSS
0.0%
2023 CWE-732 1 PoC

An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins and to connect to an attacker-specified URL using attacker-specified credentials IDs, capturing credentials stored in Jenkins. 

CVE-2023-3979
GitLab DevOps
3.1
LOW
EPSS
0.1%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.

CVE-2023-2233
GitLab DevOps
3.1
LOW
EPSS
0.1%
2023 CWE-862 1 PoC

An improper authorization issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.2.8, all versions starting from 16.3 before 16.3.5 and all versions starting from 16.4 before 16.4.1. It allows a project reporter to leak the owner's Sentry instance projects.

CVE-2023-4912
GitLab DevOps
2.6
LOW
EPSS
0.1%
2023 CWE-770 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input.

CVE-2023-2155
Air Cargo Management System DevOps Web
2.4
LOW
EPSS
0.3%
2023 CWE-79 1 PoC

A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file classes/Master.php?f=save_cargo_type. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-226276.

CVE-2023-3511
GitLab DevOps
2.0
LOW
EPSS
0.0%
2023 CWE-863 1 PoC

An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private projects they're not a member of.

CVE-2023-40453
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing an unsafe action (via escape sequence injection), or might have a data size that causes a denial of service to a bastion node. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2023-41387
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.5%
2023 1 PoC

A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses UIFileSharingEnabled and LSSupportsOpeningDocumentsInPlace properties. As a result, local users can obtain the same attack primitives as remote attackers by tampering with the internal database of the framework on the device.

CVE-2023-40344
Jenkins Delphix Plugin DevOps
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

CVE-2023-40345
Jenkins Delphix Plugin DevOps
N/A
UNKNOWN
EPSS
0.2%
2023 1 PoC

Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission to access and capture credentials they are not entitled to.

CVE-2023-43494
Jenkins DevOps
N/A
UNKNOWN
EPSS
49.1%
2023 1 PoC

Jenkins 2.50 through 2.423 (both inclusive), LTS 2.60.1 through 2.414.1 (both inclusive) does not exclude sensitive build variables (e.g., password parameter values) from the search in the build history widget, allowing attackers with Item/Read permission to obtain values of sensitive variables used in builds by iteratively testing different characters until the correct sequence is discovered.

CVE-2023-31299
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2023 1 PoC

Cross Site Scripting (XSS) vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to execute arbitrary code via the Barcode field of a container.