Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-4342 A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can … Nginx Ingress Controller 1.13.9 / 1.14.5+ Fix from $1,9502026-03-19 HIGH 8.8 CVE-2026-3288EPSS 6% A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject conf… Ingress Nginx 1.13.8 / 1.14.4+ Fix from $1,9502026-03-09 HIGH 8.1 CVE-2024-5154 A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw… Cri O Mitigation only Fix from $1,9502024-06-12 HIGH 8.8 CVE-2023-5528 A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to ad… Kubernetes 1.25.16 / 1.26.11+ Fix from $1,9502023-11-14 HIGH 8.2 CVE-2022-3172 A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to t… Apiserver 1.22.14 / 1.23.11+ Fix from $1,9502023-11-03 HIGH 8.8 CVE-2023-3893 A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escala… Csi Proxy after 1.1.2 Fix from $1,9502023-11-03 HIGH 8.8 CVE-2023-3676EPSS 12% A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on tho… Kubernetes 1.24.17 / 1.25.13+ Fix from $1,9502023-10-31 HIGH 8.8 CVE-2023-3955 A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on tho… Kubernetes 1.24.17 / 1.25.13+ Fix from $1,9502023-10-31 MEDIUM 6.3 CVE-2021-25736 Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer S… Kubernetes 1.18.18 / 1.19.10+ Fix from $1,6002023-10-30 HIGH 8.8 CVE-2023-5043 Ingress nginx annotation injection causes arbitrary command execution. Ingress Nginx 1.9.0+ Fix from $1,9502023-10-25 HIGH 8.8 CVE-2023-5044EPSS 57% Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation. Ingress Nginx 1.9.0+ Fix from $1,9502023-10-25 MEDIUM 6.5 CVE-2022-4886 Ingress-nginx `path` sanitization can be bypassed with `log_format` directive. Ingress Nginx 1.8.0+ Fix from $1,6002023-10-25 HIGH 8.8 CVE-2023-1943 Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode. Operations 1.25.4 / 1.26.2+ Fix from $1,9502023-10-12 HIGH 7.8 CVE-2022-4318 A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment vari… Cri O Mitigation only Fix from $1,9502023-09-25 HIGH 8.0 CVE-2023-1260 An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given p… Kube Apiserver Mitigation only Fix from $1,9502023-09-24 MEDIUM 5.3 CVE-2022-3466 The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-20… Cri O Mitigation only Fix from $1,6002023-09-15 MEDIUM 6.5 CVE-2023-2727 Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters ar… Kubernetes after 1.27.2 Fix from $1,6002023-07-03 MEDIUM 6.5 CVE-2023-2728 Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral … Kubernetes after 1.27.2 Fix from $1,6002023-07-03 MEDIUM 5.5 CVE-2023-2431 A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profi… Kubernetes 1.24.14 / 1.25.10+ Fix from $1,6002023-06-16 MEDIUM 5.5 CVE-2023-2878 Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs. Secrets Store Csi Driver 1.3.3+ Fix from $1,6002023-06-07 CRITICAL 9.8 CVE-2023-1174 This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube … Minikube Mitigation only Fix from $2,3002023-05-24 HIGH 7.8 CVE-2021-25749 Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true. Kubernetes 1.22.14 / 1.23.11+ Fix from $1,9502023-05-24 HIGH 7.8 CVE-2023-1944 This vulnerability enables ssh access to minikube container using a default password. Minikube after 1.29.0 Fix from $1,9502023-05-24 MEDIUM 6.5 CVE-2021-25748 A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the san… Ingress Nginx 1.2.1+ Fix from $1,6002023-05-24 HIGH 8.8 CVE-2022-3294 Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node ob… Kubernetes 1.22.16 / 1.23.14+ Fix from $1,9502023-03-01 MEDIUM 6.5 CVE-2022-3162 Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API g… Kubernetes after 1.25.3 Fix from $1,6002023-03-01 HIGH 7.1 CVE-2022-2995 Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modifica… Cri O Patch available Fix from $1,9502022-09-19 HIGH 8.8 CVE-2022-2385 A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privile… Aws Iam Authenticator 0.5.9+ Fix from $1,9502022-07-12 HIGH 7.5 CVE-2022-1708 A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync reque… Cri O 1.19.7 / 1.20.8+ Fix from $1,9502022-06-07 HIGH 8.1 CVE-2021-25745 A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path fi… Ingress Nginx 1.2.0+ Fix from $1,9502022-05-06