Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 335

Количество 335

github логотип

GHSA-mqf3-28j7-3mj6

больше 4 лет назад

Information Exposure in Kubernetes

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jmrx-5g74-6v2f

около 4 лет назад

Kubernetes client-go library logs may disclose credentials to unauthorized users

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-j3v3-cjmx-765g

23 дня назад

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-gc6w-4mgp-mgjm

9 месяцев назад

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-gc2p-g4fg-29vh

около 4 лет назад

Kubernetes did not effectively clear service account credentials

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-fp37-c92q-4pwq

около 4 лет назад

Kubernetes kube-apiserver unauthorized access

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-7w66-j2r2-vm3p

около 4 лет назад

It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-6rrr-4jqj-5947

23 дня назад

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34jx-wx69-9x8v

больше 4 лет назад

Symlink Attack in kubectl cp

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-2h9c-34v6-3qmr

около 4 лет назад

Kubernetes in OpenShift3 Access Control Misconfiguration

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2026-33519

3 месяца назад

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-13020

23 дня назад

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-13019

23 дня назад

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2025-57870

9 месяцев назад

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.

CVSS3: 10
EPSS: Низкий
ubuntu логотип

CVE-2019-11253

почти 7 лет назад

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2019-11253

почти 7 лет назад

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2019-11253

почти 7 лет назад

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2019-11253

почти 7 лет назад

Improper input validation in the Kubernetes API server in versions v1. ...

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2019-11250

почти 7 лет назад

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2019-11250

почти 7 лет назад

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-mqf3-28j7-3mj6

Information Exposure in Kubernetes

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-jmrx-5g74-6v2f

Kubernetes client-go library logs may disclose credentials to unauthorized users

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-j3v3-cjmx-765g

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVSS3: 8.1
0%
Низкий
23 дня назад
github логотип
GHSA-gc6w-4mgp-mgjm

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.

CVSS3: 10
1%
Низкий
9 месяцев назад
github логотип
GHSA-gc2p-g4fg-29vh

Kubernetes did not effectively clear service account credentials

CVSS3: 8.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-fp37-c92q-4pwq

Kubernetes kube-apiserver unauthorized access

CVSS3: 8.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-7w66-j2r2-vm3p

It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.

CVSS3: 8.1
2%
Низкий
около 4 лет назад
github логотип
GHSA-6rrr-4jqj-5947

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CVSS3: 9.8
0%
Низкий
23 дня назад
github логотип
GHSA-34jx-wx69-9x8v

Symlink Attack in kubectl cp

CVSS3: 5.5
13%
Средний
больше 4 лет назад
github логотип
GHSA-2h9c-34v6-3qmr

Kubernetes in OpenShift3 Access Control Misconfiguration

CVSS3: 3.1
1%
Низкий
около 4 лет назад
nvd логотип
CVE-2026-33519

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

CVSS3: 9.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-13020

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVSS3: 8.1
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-13019

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CVSS3: 9.8
0%
Низкий
23 дня назад
nvd логотип
CVE-2025-57870

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.

CVSS3: 10
1%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2019-11253

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

CVSS3: 7.5
26%
Средний
почти 7 лет назад
redhat логотип
CVE-2019-11253

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

CVSS3: 7.5
26%
Средний
почти 7 лет назад
nvd логотип
CVE-2019-11253

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

CVSS3: 7.5
26%
Средний
почти 7 лет назад
debian логотип
CVE-2019-11253

Improper input validation in the Kubernetes API server in versions v1. ...

CVSS3: 7.5
26%
Средний
почти 7 лет назад
ubuntu логотип
CVE-2019-11250

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

CVSS3: 6.5
2%
Низкий
почти 7 лет назад
redhat логотип
CVE-2019-11250

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

CVSS3: 4.4
2%
Низкий
почти 7 лет назад

Уязвимостей на страницу