A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can …
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject conf…
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw…
A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to ad…
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to t…
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escala…
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on tho…
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on tho…
Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer S…
Ingress nginx annotation injection causes arbitrary command execution.
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.
Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment vari…
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given p…
The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-20…
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters ar…
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral …
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profi…
Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.
This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube …
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.
This vulnerability enables ssh access to minikube container using a default password.
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the san…
Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node ob…
Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API g…
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modifica…
A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privile…
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync reque…
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path fi…