Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Weave Desktop HIGH 7.8
CVE-2024-25545

An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework component.

Fix: after 7.84.1
Fix from $1,950 2024-04-12
Gitops Terraform Controller MEDIUM 6.5
CVE-2023-34236

Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in a GitOps way. A vulnerabilit…

Fix: 0.14.4+
Fix from $1,600 2023-07-14
Weave Gitops MEDIUM 6.0
CVE-2022-23509

Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. GitOps r…

Fix: 0.12.0+
Fix from $1,600 2023-01-09
Weave Gitops HIGH 7.8
CVE-2022-23508

Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulne…

Fix: 0.12.0+
Fix from $1,950 2023-01-09
Gitops Tools CRITICAL 9.8
CVE-2022-35976

The GitOps Tools Extension for VSCode relies on kubeconfigs in order to communicate with Kubernetes clusters. A specially crafted kubeconfig leads to…

Fix: after 0.20.9
Fix from $2,300 2022-08-18
Gitops Tools CRITICAL 9.8
CVE-2022-35975

The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution …

Fix: after 0.20.2
Fix from $2,300 2022-08-18
Weave Gitops HIGH 7.5
CVE-2022-31098

Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulner…

Fix: 0.8.1+
Fix from $1,950 2022-06-27
Weave HIGH 8.0
CVE-2020-26278

Weave Net is open source software which creates a virtual network that connects Docker containers across multiple hosts and enables their automatic d…

Fix: 2.8.0+
Fix from $1,950 2021-01-20
Cloud Agent CRITICAL 9.8
CVE-2020-35464

Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weav…

Mitigation only
Fix from $2,300 2020-12-15
Weave Net MEDIUM 5.8
CVE-2020-11091

In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS requests from the host and ther…

Fix: 2.6.3+
Fix from $1,600 2020-06-03