Kubernetes — открытое программное обеспечение для оркестровки контейнеризированных приложений — автоматизации их развёртывания, масштабирования и координации в условиях кластера.
Релизный цикл, информация об уязвимостях
График релизов
Количество 326
GHSA-fqg2-c97r-rqcj
Exposure of Sensitive Information in Jenkins Kubernetes Plugin
GHSA-7w66-j2r2-vm3p
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
GHSA-rqgw-vh6p-qf7j
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
GHSA-mm7g-f2gg-cw8g
Kubernetes arbitrary file overwrite
GHSA-2jq6-ffph-p4h8
Kubernetes arbitrary file overwrite
GHSA-6g96-g4m6-hw69
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.
GHSA-q4rr-64r9-fwgf
Kubernetes DoS Vulnerability
GHSA-2h9c-34v6-3qmr
Kubernetes in OpenShift3 Access Control Misconfiguration
GHSA-mqf3-28j7-3mj6
Information Exposure in Kubernetes
GHSA-2575-pghm-6qqx
Kubernetes Unsafe Cacheing
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-fqg2-c97r-rqcj Exposure of Sensitive Information in Jenkins Kubernetes Plugin | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-7w66-j2r2-vm3p It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate. | CVSS3: 8.1 | 0% Низкий | больше 3 лет назад | |
GHSA-rqgw-vh6p-qf7j In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem. | CVSS3: 9.6 | 32% Средний | больше 3 лет назад | |
GHSA-mm7g-f2gg-cw8g Kubernetes arbitrary file overwrite | CVSS3: 5.6 | 0% Низкий | больше 3 лет назад | |
GHSA-2jq6-ffph-p4h8 Kubernetes arbitrary file overwrite | CVSS3: 5.5 | 1% Низкий | больше 3 лет назад | |
GHSA-6g96-g4m6-hw69 Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-q4rr-64r9-fwgf Kubernetes DoS Vulnerability | CVSS3: 6.5 | 11% Средний | больше 3 лет назад | |
GHSA-2h9c-34v6-3qmr Kubernetes in OpenShift3 Access Control Misconfiguration | CVSS3: 3.1 | 0% Низкий | больше 3 лет назад | |
GHSA-mqf3-28j7-3mj6 Information Exposure in Kubernetes | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-2575-pghm-6qqx Kubernetes Unsafe Cacheing | CVSS3: 5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу