Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2021-25746 A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress o… Ingress Nginx 1.2.0+ Fix from $1,9502022-05-06 MEDIUM 5.3 CVE-2022-27652 A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker En… Cri O 20.10.14+ Fix from $1,6002022-04-18 HIGH 8.8 CVE-2022-0811EPSS 19% A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster th… Cri O 1.19.6 / 1.20.7+ Fix from $1,9502022-03-16 HIGH 7.1 CVE-2021-25742 A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain… Ingress Nginx 0.49.1+ Fix from $1,9502021-10-29 MEDIUM 6.7 CVE-2021-25738 Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. Java 11.0.1+ Fix from $1,6002021-10-11 HIGH 8.1 CVE-2021-25741EPSS 8% A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories… Kubernetes after 1.22.1 Fix from $1,9502021-09-20 MEDIUM 6.5 CVE-2021-25735EPSS 6% A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected … Kubernetes 1.18.18 / 1.19.10+ Fix from $1,6002021-09-06 CRITICAL 9.1 CVE-2020-8570 Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying mu… Java 9.0.2 / 10.0.1+ Fix from $2,3002021-01-21 MEDIUM 6.5 CVE-2020-8568 Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the … Secrets Store Csi Driver Patch available Fix from $1,6002021-01-21 MEDIUM 6.5 CVE-2020-8569 Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot… Container Storage Interface Snapshotter 2.1.3 / 3.0.2+ Fix from $1,6002021-01-21 MEDIUM 5.0 CVE-2020-8554EPSS 9% Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept tr… Kubernetes Patch available Fix from $1,6002021-01-21 MEDIUM 5.5 CVE-2020-8563 In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the clo… Kubernetes 1.19.3+ Fix from $1,6002020-12-07 MEDIUM 5.5 CVE-2020-8564 In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker confi… Kubernetes 1.17.13 / 1.18.10+ Fix from $1,6002020-12-07 MEDIUM 5.5 CVE-2020-8565 In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API se… Kubernetes after 1.19.3 Fix from $1,6002020-12-07 MEDIUM 5.5 CVE-2020-8566 In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This… Kubernetes 1.17.13 / 1.18.10+ Fix from $1,6002020-12-07 MEDIUM 5.9 CVE-2020-8553 The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress obj… Ingress Nginx 0.28.0+ Fix from $1,6002020-07-29 HIGH 8.8 CVE-2020-8558 The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows… Kubernetes after 1.18.3 Fix from $1,9502020-07-27 MEDIUM 5.5 CVE-2020-8557 The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its … Kubernetes 1.16.13 / 1.17.9+ Fix from $1,6002020-07-23 MEDIUM 6.5 CVE-2019-11252 The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and even… Kubernetes after 1.17.0 Fix from $1,6002020-07-23 MEDIUM 6.8 CVE-2020-8559EPSS 6% The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect o… Kubernetes 1.16.13 / 1.17.9+ Fix from $1,6002020-07-22 MEDIUM 6.3 CVE-2020-8555 The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a S… Kubernetes 1.15.11 / 1.16.9+ Fix from $1,6002020-06-05 MEDIUM 6.5 CVE-2019-11254 The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malici… Kubernetes 1.15.10 / 1.16.7+ Fix from $1,6002020-04-01 MEDIUM 6.5 CVE-2020-8551 The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via t… Kubernetes after 1.17.2 Fix from $1,6002020-03-27 MEDIUM 5.7 CVE-2019-11251 The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provid… Kubernetes 1.13.11 / 1.14.7+ Fix from $1,6002020-02-03 MEDIUM 5.3 CVE-2018-1002104 Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly. Nginx Ingress Controller 1.5.0+ Fix from $1,6002020-01-14 MEDIUM 6.5 CVE-2019-11255 Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshot… External Provisioner after 1.2.1 Fix from $1,6002019-12-05 MEDIUM 5.0 CVE-2019-14891 A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (… Cri O 1.16.1+ Fix from $1,6002019-11-25 MEDIUM 6.5 CVE-2019-10223 A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that en… Kube State Metrics No fix yet Fix from $1,6002019-11-05 HIGH 7.5 CVE-2019-11253EPSS 26% Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows aut… Kubernetes 1.13.12 / 1.14.8+ Fix from $1,9502019-10-17 HIGH 8.2 CVE-2019-11248EPSS 75% The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's hea… Kubernetes 1.12.10+ Fix from $1,9502019-08-29