Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 339

Количество 339

github логотип

GHSA-pmqp-h87c-mr78

больше 5 лет назад

XML Entity Expansion and Improper Input Validation in Kubernetes API server

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-mqf3-28j7-3mj6

больше 4 лет назад

Information Exposure in Kubernetes

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-jmrx-5g74-6v2f

больше 4 лет назад

Kubernetes client-go library logs may disclose credentials to unauthorized users

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-j3v3-cjmx-765g

2 месяца назад

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-gc6w-4mgp-mgjm

11 месяцев назад

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-gc2p-g4fg-29vh

больше 4 лет назад

Kubernetes did not effectively clear service account credentials

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-fp37-c92q-4pwq

больше 4 лет назад

Kubernetes kube-apiserver unauthorized access

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-7w66-j2r2-vm3p

больше 4 лет назад

It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-6rrr-4jqj-5947

2 месяца назад

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-34jx-wx69-9x8v

больше 4 лет назад

Symlink Attack in kubectl cp

CVSS3: 5.5
EPSS: Средний
github логотип

GHSA-2h9c-34v6-3qmr

больше 4 лет назад

Kubernetes in OpenShift3 Access Control Misconfiguration

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2026-33519

5 месяцев назад

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-13020

2 месяца назад

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-13019

2 месяца назад

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2025-57870

11 месяцев назад

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.

CVSS3: 10
EPSS: Низкий
ubuntu логотип

CVE-2019-11253

почти 7 лет назад

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2019-11253

почти 7 лет назад

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2019-11253

почти 7 лет назад

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2019-11253

почти 7 лет назад

Improper input validation in the Kubernetes API server in versions v1. ...

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2019-11250

около 7 лет назад

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-pmqp-h87c-mr78

XML Entity Expansion and Improper Input Validation in Kubernetes API server

CVSS3: 7.5
26%
Средний
больше 5 лет назад
github логотип
GHSA-mqf3-28j7-3mj6

Information Exposure in Kubernetes

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-jmrx-5g74-6v2f

Kubernetes client-go library logs may disclose credentials to unauthorized users

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-j3v3-cjmx-765g

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVSS3: 8.1
0%
Низкий
2 месяца назад
github логотип
GHSA-gc6w-4mgp-mgjm

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.

CVSS3: 10
1%
Низкий
11 месяцев назад
github логотип
GHSA-gc2p-g4fg-29vh

Kubernetes did not effectively clear service account credentials

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-fp37-c92q-4pwq

Kubernetes kube-apiserver unauthorized access

CVSS3: 8.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-7w66-j2r2-vm3p

It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.

CVSS3: 8.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-6rrr-4jqj-5947

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CVSS3: 9.8
0%
Низкий
2 месяца назад
github логотип
GHSA-34jx-wx69-9x8v

Symlink Attack in kubectl cp

CVSS3: 5.5
13%
Средний
больше 4 лет назад
github логотип
GHSA-2h9c-34v6-3qmr

Kubernetes in OpenShift3 Access Control Misconfiguration

CVSS3: 3.1
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2026-33519

An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kubernetes that did not correctly check permissions assigned to developer credentials.

CVSS3: 9.8
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-13020

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for an administrator to reset a user’s password remains unchanged.

CVSS3: 8.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-13019

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API.

CVSS3: 9.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-57870

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGIS Feature Service operation. Successful exploitation can potentially result in unauthorized access, modification, or deletion of data from the underlying Enterprise Geodatabase.

CVSS3: 10
1%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2019-11253

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

CVSS3: 7.5
26%
Средний
почти 7 лет назад
redhat логотип
CVE-2019-11253

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

CVSS3: 7.5
26%
Средний
почти 7 лет назад
nvd логотип
CVE-2019-11253

Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.

CVSS3: 7.5
26%
Средний
почти 7 лет назад
debian логотип
CVE-2019-11253

Improper input validation in the Kubernetes API server in versions v1. ...

CVSS3: 7.5
26%
Средний
почти 7 лет назад
ubuntu логотип
CVE-2019-11250

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected.

CVSS3: 6.5
2%
Низкий
около 7 лет назад

Уязвимостей на страницу