Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kubernetes HIGH 8.1
CVE-2019-11247

The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced.…

Fix: 1.13.9 / 1.14.5+
Fix from $1,950 2019-08-29
Kubernetes HIGH 7.8
CVE-2019-11245

In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or…

Patch available
Fix from $1,950 2019-08-29
Kubernetes MEDIUM 6.5
CVE-2019-11246

The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the c…

Fix: 1.13.9 / 1.14.5+
Fix from $1,600 2019-08-29
Kubernetes MEDIUM 6.5
CVE-2019-11249

The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the c…

Fix: 1.13.9 / 1.14.5+
Fix from $1,600 2019-08-29
Kubernetes MEDIUM 6.5
CVE-2019-11250

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via log…

Fix: 1.15.3+
Fix from $1,600 2019-08-29
Kubernetes HIGH 8.1
CVE-2019-11243

In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (b…

Fix: after 1.12.4
Fix from $1,950 2019-04-22
Kubernetes MEDIUM 5.0
CVE-2019-11244

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), writt…

Fix: after 1.14.1
Fix from $1,600 2019-04-22
Kubernetes HIGH 7.5
CVE-2019-9946

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes.…

Fix: 0.7.5 / 1.11.9+
Fix from $1,950 2019-04-02
Kubernetes MEDIUM 6.5
CVE-2019-1002100EPSS 10%

In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can …

Fix: 1.11.8 / 1.12.6+
Fix from $1,600 2019-04-01
Kubernetes MEDIUM 5.5
CVE-2019-1002101EPSS 13%

The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside …

Fix: 1.11.9 / 1.12.7+
Fix from $1,600 2019-04-01
Dashboard HIGH 7.5
CVE-2018-18264EPSS 70%

Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the clust…

Fix: 1.10.1+
Fix from $1,950 2019-01-03
Kubernetes CRITICAL 9.8
CVE-2018-1002101

In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Windows nod…

Fix: after 1.11.1
Fix from $2,300 2018-12-05
Kubernetes CRITICAL 9.8
CVE-2018-1002105EPSS 87%

In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-api…

Fix: after 1.12.2
Fix from $2,300 2018-12-05
Minikube HIGH 8.8
CVE-2018-1002103

In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM environments where the IP is…

Fix: after 0.29.0
Fix from $1,950 2018-12-05
Kubernetes HIGH 8.1
CVE-2016-7075

It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An …

Patch available
Fix from $1,950 2018-09-10
Kubernetes MEDIUM 5.5
CVE-2018-1002100

In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the c…

Fix: after 1.9.5
Fix from $1,600 2018-06-02
Cri O HIGH 8.8
CVE-2018-1000400

Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities th…

Fix: 1.9.0+
Fix from $1,950 2018-05-18
Kubernetes CRITICAL 9.6
CVE-2017-1002101EPSS 12%

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volum…

Fix: 1.7.14 / 1.8.9+
Fix from $2,300 2018-03-13
Kubernetes MEDIUM 5.6
CVE-2017-1002102

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or do…

Fix: 1.7.14 / 1.8.9+
Fix from $1,600 2018-03-13
Kubernetes MEDIUM 6.5
CVE-2017-1002100

Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "contain…

Patch available
Fix from $1,600 2017-09-14
Kubernetes CRITICAL 9.8
CVE-2017-1000056

Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use…

Mitigation only
Fix from $2,300 2017-07-17
Kubernetes MEDIUM 5.3
CVE-2015-7528

Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name.

Fix: after 1.2.0
Fix from $1,600 2016-04-11
Kubernetes CRITICAL 9.8
CVE-2016-1906

Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not al…

Patch available
Fix from $2,300 2016-02-03
Kubernetes HIGH 7.7
CVE-2016-1905

The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a …

Mitigation only
Fix from $1,950 2016-02-03