Kubernetes — открытое программное обеспечение для оркестровки контейнеризированных приложений — автоматизации их развёртывания, масштабирования и координации в условиях кластера.
Релизный цикл, информация об уязвимостях
График релизов
Количество 326
GHSA-rr6j-37cv-c7x7
Missing Authorization in Jenkins Kubernetes Plugin
GHSA-fh5w-p2j4-4p8x
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin
GHSA-fp37-c92q-4pwq
Kubernetes kube-apiserver unauthorized access
GHSA-v8c4-hw4j-x4pr
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user?s machine. If the tar binary in the container is malicious, it could run any code and output unexpected, malicious results. An attacker could use this to write files to any path on the user?s machine when kubectl cp is called, limited only by the system permissions of the local user. Kubernetes affected versions include versions prior to 1.13.9, versions prior to 1.14.5, versions prior to 1.15.2, and versions 1.1, 1.2, 1.4, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9, 1.10, 1.11, 1.12.
GHSA-jmrx-5g74-6v2f
Kubernetes client-go library logs may disclose credentials to unauthorized users
GHSA-9frv-h2cf-52wh
The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.
GHSA-8wj5-gvvw-f5fh
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user?s machine. If the tar binary in the container is malicious, it could run any code and output unexpected, malicious results. An attacker could use this to write files to any path on the user?s machine when kubectl cp is called, limited only by the system permissions of the local user. Kubernetes affected versions include versions prior to 1.12.9, versions prior to 1.13.6, versions prior to 1.14.2, and versions 1.1, 1.2, 1.4, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9, 1.10, 1.11.
GHSA-gc2p-g4fg-29vh
Kubernetes did not effectively clear service account credentials
GHSA-rj88-p797-v9xw
Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to the URI string requires privileged access to the Kubernetes cluster or authenticated access to the Azure portal.
GHSA-v67x-gpg7-mwv3
Exposure of Sensitive Information in Jenkins Kubernetes Plugin
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-rr6j-37cv-c7x7 Missing Authorization in Jenkins Kubernetes Plugin | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-fh5w-p2j4-4p8x Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-fp37-c92q-4pwq Kubernetes kube-apiserver unauthorized access | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад | |
GHSA-v8c4-hw4j-x4pr The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user?s machine. If the tar binary in the container is malicious, it could run any code and output unexpected, malicious results. An attacker could use this to write files to any path on the user?s machine when kubectl cp is called, limited only by the system permissions of the local user. Kubernetes affected versions include versions prior to 1.13.9, versions prior to 1.14.5, versions prior to 1.15.2, and versions 1.1, 1.2, 1.4, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9, 1.10, 1.11, 1.12. | 3% Низкий | больше 3 лет назад | ||
GHSA-jmrx-5g74-6v2f Kubernetes client-go library logs may disclose credentials to unauthorized users | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-9frv-h2cf-52wh The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration. | CVSS3: 8.2 | 91% Критический | больше 3 лет назад | |
GHSA-8wj5-gvvw-f5fh The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user?s machine. If the tar binary in the container is malicious, it could run any code and output unexpected, malicious results. An attacker could use this to write files to any path on the user?s machine when kubectl cp is called, limited only by the system permissions of the local user. Kubernetes affected versions include versions prior to 1.12.9, versions prior to 1.13.6, versions prior to 1.14.2, and versions 1.1, 1.2, 1.4, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9, 1.10, 1.11. | 2% Низкий | больше 3 лет назад | ||
GHSA-gc2p-g4fg-29vh Kubernetes did not effectively clear service account credentials | CVSS3: 8.1 | 0% Низкий | больше 3 лет назад | |
GHSA-rj88-p797-v9xw Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to the URI string requires privileged access to the Kubernetes cluster or authenticated access to the Azure portal. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-v67x-gpg7-mwv3 Exposure of Sensitive Information in Jenkins Kubernetes Plugin | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу