Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2019-11247 The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced.… Kubernetes 1.13.9 / 1.14.5+ Fix from $1,9502019-08-29 HIGH 7.8 CVE-2019-11245 In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or… Kubernetes Patch available Fix from $1,9502019-08-29 MEDIUM 6.5 CVE-2019-11246 The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the c… Kubernetes 1.13.9 / 1.14.5+ Fix from $1,6002019-08-29 MEDIUM 6.5 CVE-2019-11249 The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the c… Kubernetes 1.13.9 / 1.14.5+ Fix from $1,6002019-08-29 MEDIUM 6.5 CVE-2019-11250 The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via log… Kubernetes 1.15.3+ Fix from $1,6002019-08-29 HIGH 8.1 CVE-2019-11243 In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (b… Kubernetes after 1.12.4 Fix from $1,9502019-04-22 MEDIUM 5.0 CVE-2019-11244 In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), writt… Kubernetes after 1.14.1 Fix from $1,6002019-04-22 HIGH 7.5 CVE-2019-9946 Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes.… Kubernetes 0.7.5 / 1.11.9+ Fix from $1,9502019-04-02 MEDIUM 6.5 CVE-2019-1002100EPSS 10% In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can … Kubernetes 1.11.8 / 1.12.6+ Fix from $1,6002019-04-01 MEDIUM 5.5 CVE-2019-1002101EPSS 13% The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside … Kubernetes 1.11.9 / 1.12.7+ Fix from $1,6002019-04-01 HIGH 7.5 CVE-2018-18264EPSS 70% Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the clust… Dashboard 1.10.1+ Fix from $1,9502019-01-03 CRITICAL 9.8 CVE-2018-1002101 In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Windows nod… Kubernetes after 1.11.1 Fix from $2,3002018-12-05 CRITICAL 9.8 CVE-2018-1002105EPSS 87% In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-api… Kubernetes after 1.12.2 Fix from $2,3002018-12-05 HIGH 8.8 CVE-2018-1002103 In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM environments where the IP is… Minikube after 0.29.0 Fix from $1,9502018-12-05 HIGH 8.1 CVE-2016-7075 It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An … Kubernetes Patch available Fix from $1,9502018-09-10 MEDIUM 5.5 CVE-2018-1002100 In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the c… Kubernetes after 1.9.5 Fix from $1,6002018-06-02 HIGH 8.8 CVE-2018-1000400 Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities th… Cri O 1.9.0+ Fix from $1,9502018-05-18 CRITICAL 9.6 CVE-2017-1002101EPSS 12% In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volum… Kubernetes 1.7.14 / 1.8.9+ Fix from $2,3002018-03-13 MEDIUM 5.6 CVE-2017-1002102 In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or do… Kubernetes 1.7.14 / 1.8.9+ Fix from $1,6002018-03-13 MEDIUM 6.5 CVE-2017-1002100 Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "contain… Kubernetes Patch available Fix from $1,6002017-09-14 CRITICAL 9.8 CVE-2017-1000056 Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use… Kubernetes Mitigation only Fix from $2,3002017-07-17 MEDIUM 5.3 CVE-2015-7528 Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name. Kubernetes after 1.2.0 Fix from $1,6002016-04-11 CRITICAL 9.8 CVE-2016-1906 Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not al… Kubernetes Patch available Fix from $2,3002016-02-03 HIGH 7.7 CVE-2016-1905 The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a … Kubernetes Mitigation only Fix from $1,9502016-02-03