Логотип exploitDog
product: "kubernetes"
Консоль
Логотип exploitDog

exploitDog

product: "kubernetes"

Количество 326

Количество 326

github логотип

GHSA-qhm4-jxv7-j9pq

почти 4 года назад

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-qh36-44jv-c8xj

почти 4 года назад

Potential proxy IP restriction bypass in Kubernetes

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-qc2g-gmh6-95p4

больше 2 лет назад

kube-apiserver vulnerable to policy bypass

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q78c-gwqw-jcmc

около 2 лет назад

Kubernetes privilege escalation vulnerability

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-mm7g-f2gg-cw8g

больше 3 лет назад

Kubernetes arbitrary file overwrite

CVSS3: 5.6
EPSS: Низкий
github логотип

GHSA-mfv7-gq43-w965

больше 4 лет назад

Incomplete List of Disallowed Inputs in Kubernetes

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-m3fm-h5jp-q79p

почти 4 года назад

Authorization bypass in Openshift

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-jh36-q97c-9928

почти 3 года назад

Kubernetes vulnerable to validation bypass

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-hq6q-c2x6-hmch

около 2 лет назад

Kubernetes Improper Input Validation vulnerability

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-g42g-737j-qx6j

больше 4 лет назад

Access Restriction Bypass in kube-apiserver

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-g2r3-4g8q-h5rj

больше 3 лет назад

Missing authorization in Jenkins Kubernetes Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fqg2-c97r-rqcj

больше 3 лет назад

Exposure of Sensitive Information in Jenkins Kubernetes Plugin

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-fh5w-p2j4-4p8x

больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-f9jg-8p32-2f55

почти 4 года назад

kubectl ANSI escape characters not filtered

CVSS3: 3
EPSS: Низкий
github логотип

GHSA-f5f7-6478-qm6p

около 4 лет назад

Files or Directories Accessible to External Parties in kubernetes

CVSS3: 8.1
EPSS: Средний
github логотип

GHSA-cgcv-5272-97pr

больше 2 лет назад

Kubernetes mountable secrets policy bypass

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9frv-h2cf-52wh

больше 3 лет назад

The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.

CVSS3: 8.2
EPSS: Критический
github логотип

GHSA-8wj5-gvvw-f5fh

больше 3 лет назад

The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user?s machine. If the tar binary in the container is malicious, it could run any code and output unexpected, malicious results. An attacker could use this to write files to any path on the user?s machine when kubectl cp is called, limited only by the system permissions of the local user. Kubernetes affected versions include versions prior to 1.12.9, versions prior to 1.13.6, versions prior to 1.14.2, and versions 1.1, 1.2, 1.4, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9, 1.10, 1.11.

EPSS: Низкий
github логотип

GHSA-8mjg-8c8g-6h85

почти 3 года назад

Kubernetes Sensitive Information leak via Log File

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-8cfg-vx93-jvxw

почти 3 года назад

Kubernetes client-go vulnerable to Sensitive Information Leak via Log File

CVSS3: 4.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-qhm4-jxv7-j9pq

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

CVSS3: 4.3
1%
Низкий
почти 4 года назад
github логотип
GHSA-qh36-44jv-c8xj

Potential proxy IP restriction bypass in Kubernetes

CVSS3: 3.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-qc2g-gmh6-95p4

kube-apiserver vulnerable to policy bypass

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-q78c-gwqw-jcmc

Kubernetes privilege escalation vulnerability

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-mm7g-f2gg-cw8g

Kubernetes arbitrary file overwrite

CVSS3: 5.6
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mfv7-gq43-w965

Incomplete List of Disallowed Inputs in Kubernetes

CVSS3: 4.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-m3fm-h5jp-q79p

Authorization bypass in Openshift

CVSS3: 9.8
2%
Низкий
почти 4 года назад
github логотип
GHSA-jh36-q97c-9928

Kubernetes vulnerable to validation bypass

CVSS3: 8.8
1%
Низкий
почти 3 года назад
github логотип
GHSA-hq6q-c2x6-hmch

Kubernetes Improper Input Validation vulnerability

CVSS3: 8.8
19%
Средний
около 2 лет назад
github логотип
GHSA-g42g-737j-qx6j

Access Restriction Bypass in kube-apiserver

CVSS3: 6.5
18%
Средний
больше 4 лет назад
github логотип
GHSA-g2r3-4g8q-h5rj

Missing authorization in Jenkins Kubernetes Plugin

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fqg2-c97r-rqcj

Exposure of Sensitive Information in Jenkins Kubernetes Plugin

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fh5w-p2j4-4p8x

Exposure of Sensitive Information to an Unauthorized Actor in Jenkins Kubernetes Plugin

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-f9jg-8p32-2f55

kubectl ANSI escape characters not filtered

CVSS3: 3
0%
Низкий
почти 4 года назад
github логотип
GHSA-f5f7-6478-qm6p

Files or Directories Accessible to External Parties in kubernetes

CVSS3: 8.1
33%
Средний
около 4 лет назад
github логотип
GHSA-cgcv-5272-97pr

Kubernetes mountable secrets policy bypass

CVSS3: 6.5
5%
Низкий
больше 2 лет назад
github логотип
GHSA-9frv-h2cf-52wh

The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, and 1.12.10 are affected. The issue is of medium severity, but not exposed by the default configuration.

CVSS3: 8.2
91%
Критический
больше 3 лет назад
github логотип
GHSA-8wj5-gvvw-f5fh

The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user?s machine. If the tar binary in the container is malicious, it could run any code and output unexpected, malicious results. An attacker could use this to write files to any path on the user?s machine when kubectl cp is called, limited only by the system permissions of the local user. Kubernetes affected versions include versions prior to 1.12.9, versions prior to 1.13.6, versions prior to 1.14.2, and versions 1.1, 1.2, 1.4, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9, 1.10, 1.11.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-8mjg-8c8g-6h85

Kubernetes Sensitive Information leak via Log File

CVSS3: 4.7
0%
Низкий
почти 3 года назад
github логотип
GHSA-8cfg-vx93-jvxw

Kubernetes client-go vulnerable to Sensitive Information Leak via Log File

CVSS3: 4.7
0%
Низкий
почти 3 года назад

Уязвимостей на страницу