Логотип exploitDog
product: "kubernetes"
Консоль
Логотип exploitDog

exploitDog

product: "kubernetes"
Kubernetes

Kubernetesоткрытое программное обеспечение для оркестровки контейнеризированных приложений — автоматизации их развёртывания, масштабирования и координации в условиях кластера.

Релизный цикл, информация об уязвимостях

Продукт: Kubernetes
Вендор: kubernetes

График релизов

1.321.331.342024202520262027

Недавние уязвимости Kubernetes

Количество 326

github логотип

GHSA-fqg2-c97r-rqcj

больше 3 лет назад

Exposure of Sensitive Information in Jenkins Kubernetes Plugin

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-7w66-j2r2-vm3p

больше 3 лет назад

It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-rqgw-vh6p-qf7j

больше 3 лет назад

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.

CVSS3: 9.6
EPSS: Средний
github логотип

GHSA-mm7g-f2gg-cw8g

больше 3 лет назад

Kubernetes arbitrary file overwrite

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-2jq6-ffph-p4h8

больше 3 лет назад

Kubernetes arbitrary file overwrite

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-6g96-g4m6-hw69

больше 3 лет назад

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-q4rr-64r9-fwgf

больше 3 лет назад

Kubernetes DoS Vulnerability

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-2h9c-34v6-3qmr

больше 3 лет назад

Kubernetes in OpenShift3 Access Control Misconfiguration

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-mqf3-28j7-3mj6

больше 3 лет назад

Information Exposure in Kubernetes

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2575-pghm-6qqx

больше 3 лет назад

Kubernetes Unsafe Cacheing

CVSS3: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-fqg2-c97r-rqcj

Exposure of Sensitive Information in Jenkins Kubernetes Plugin

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-7w66-j2r2-vm3p

It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-rqgw-vh6p-qf7j

In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.

CVSS3: 9.6
32%
Средний
больше 3 лет назад
github логотип
GHSA-mm7g-f2gg-cw8g

Kubernetes arbitrary file overwrite

CVSS3: 5.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2jq6-ffph-p4h8

Kubernetes arbitrary file overwrite

CVSS3: 5.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-6g96-g4m6-hw69

Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-q4rr-64r9-fwgf

Kubernetes DoS Vulnerability

CVSS3: 6.5
11%
Средний
больше 3 лет назад
github логотип
GHSA-2h9c-34v6-3qmr

Kubernetes in OpenShift3 Access Control Misconfiguration

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mqf3-28j7-3mj6

Information Exposure in Kubernetes

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2575-pghm-6qqx

Kubernetes Unsafe Cacheing

CVSS3: 5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться