Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ingress Nginx HIGH 7.1
CVE-2021-25746

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress o…

Fix: 1.2.0+
Fix from $1,950 2022-05-06
Cri O MEDIUM 5.3
CVE-2022-27652

A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker En…

Fix: 20.10.14+
Fix from $1,600 2022-04-18
Cri O HIGH 8.8
CVE-2022-0811EPSS 19%

A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster th…

Fix: 1.19.6 / 1.20.7+
Fix from $1,950 2022-03-16
Ingress Nginx HIGH 7.1
CVE-2021-25742

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain…

Fix: 0.49.1+
Fix from $1,950 2021-10-29
Java MEDIUM 6.7
CVE-2021-25738

Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.

Fix: 11.0.1+
Fix from $1,600 2021-10-11
Kubernetes HIGH 8.1
CVE-2021-25741EPSS 8%

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories…

Fix: after 1.22.1
Fix from $1,950 2021-09-20
Kubernetes MEDIUM 6.5
CVE-2021-25735EPSS 6%

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected …

Fix: 1.18.18 / 1.19.10+
Fix from $1,600 2021-09-06
Java CRITICAL 9.1
CVE-2020-8570

Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying mu…

Fix: 9.0.2 / 10.0.1+
Fix from $2,300 2021-01-21
Secrets Store Csi Driver MEDIUM 6.5
CVE-2020-8568

Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the …

Patch available
Fix from $1,600 2021-01-21
Container Storage Interface Snapshotter MEDIUM 6.5
CVE-2020-8569

Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot…

Fix: 2.1.3 / 3.0.2+
Fix from $1,600 2021-01-21
Kubernetes MEDIUM 5.0
CVE-2020-8554EPSS 9%

Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept tr…

Patch available
Fix from $1,600 2021-01-21
Kubernetes MEDIUM 5.5
CVE-2020-8563

In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the clo…

Fix: 1.19.3+
Fix from $1,600 2020-12-07
Kubernetes MEDIUM 5.5
CVE-2020-8564

In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker confi…

Fix: 1.17.13 / 1.18.10+
Fix from $1,600 2020-12-07
Kubernetes MEDIUM 5.5
CVE-2020-8565

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API se…

Fix: after 1.19.3
Fix from $1,600 2020-12-07
Kubernetes MEDIUM 5.5
CVE-2020-8566

In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This…

Fix: 1.17.13 / 1.18.10+
Fix from $1,600 2020-12-07
Ingress Nginx MEDIUM 5.9
CVE-2020-8553

The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress obj…

Fix: 0.28.0+
Fix from $1,600 2020-07-29
Kubernetes HIGH 8.8
CVE-2020-8558

The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows…

Fix: after 1.18.3
Fix from $1,950 2020-07-27
Kubernetes MEDIUM 5.5
CVE-2020-8557

The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its …

Fix: 1.16.13 / 1.17.9+
Fix from $1,600 2020-07-23
Kubernetes MEDIUM 6.5
CVE-2019-11252

The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and even…

Fix: after 1.17.0
Fix from $1,600 2020-07-23
Kubernetes MEDIUM 6.8
CVE-2020-8559EPSS 6%

The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect o…

Fix: 1.16.13 / 1.17.9+
Fix from $1,600 2020-07-22
Kubernetes MEDIUM 6.3
CVE-2020-8555

The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a S…

Fix: 1.15.11 / 1.16.9+
Fix from $1,600 2020-06-05
Kubernetes MEDIUM 6.5
CVE-2019-11254

The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malici…

Fix: 1.15.10 / 1.16.7+
Fix from $1,600 2020-04-01
Kubernetes MEDIUM 6.5
CVE-2020-8551

The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via t…

Fix: after 1.17.2
Fix from $1,600 2020-03-27
Kubernetes MEDIUM 5.7
CVE-2019-11251

The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provid…

Fix: 1.13.11 / 1.14.7+
Fix from $1,600 2020-02-03
Nginx Ingress Controller MEDIUM 5.3
CVE-2018-1002104

Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.

Fix: 1.5.0+
Fix from $1,600 2020-01-14
External Provisioner MEDIUM 6.5
CVE-2019-11255

Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshot…

Fix: after 1.2.1
Fix from $1,600 2019-12-05
Cri O MEDIUM 5.0
CVE-2019-14891

A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (…

Fix: 1.16.1+
Fix from $1,600 2019-11-25
Kube State Metrics MEDIUM 6.5
CVE-2019-10223

A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that en…

No fix yet
Fix from $1,600 2019-11-05
Kubernetes HIGH 7.5
CVE-2019-11253EPSS 26%

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows aut…

Fix: 1.13.12 / 1.14.8+
Fix from $1,950 2019-10-17
Kubernetes HIGH 8.2
CVE-2019-11248EPSS 75%

The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's hea…

Fix: 1.12.10+
Fix from $1,950 2019-08-29