Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 339

Количество 339

nvd логотип

CVE-2022-3294

больше 3 лет назад

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server's private network.

CVSS3: 6.6
EPSS: Низкий
debian логотип

CVE-2022-3294

больше 3 лет назад

Users may have access to secure endpoints in the control plane network ...

CVSS3: 6.6
EPSS: Низкий
ubuntu логотип

CVE-2022-3162

больше 3 лет назад

Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are true: 1. There are 2+ CustomResourceDefinitions sharing the same API group 2. Users have cluster-wide list or watch authorization on one of those custom resources. 3. The same users are not authorized to read another custom resource in the same API group.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-3162

почти 4 года назад

Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are true: 1. There are 2+ CustomResourceDefinitions sharing the same API group 2. Users have cluster-wide list or watch authorization on one of those custom resources. 3. The same users are not authorized to read another custom resource in the same API group.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-3162

больше 3 лет назад

Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are true: 1. There are 2+ CustomResourceDefinitions sharing the same API group 2. Users have cluster-wide list or watch authorization on one of those custom resources. 3. The same users are not authorized to read another custom resource in the same API group.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-3162

больше 3 лет назад

Users authorized to list or watch one type of namespaced custom resour ...

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-25749

около 4 лет назад

Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.

CVSS3: 3.8
EPSS: Низкий
nvd логотип

CVE-2021-25749

больше 3 лет назад

Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2021-25749

больше 3 лет назад

Windows workloads can run as ContainerAdministrator even when those wo ...

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2021-25743

больше 4 лет назад

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
EPSS: Низкий
redhat логотип

CVE-2021-25743

больше 4 лет назад

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
EPSS: Низкий
nvd логотип

CVE-2021-25743

больше 4 лет назад

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
EPSS: Низкий
debian логотип

CVE-2021-25743

больше 4 лет назад

kubectl does not neutralize escape, meta or control sequences containe ...

CVSS3: 3
EPSS: Низкий
ubuntu логотип

CVE-2021-25741

почти 5 лет назад

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2021-25741

почти 5 лет назад

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-25741

почти 5 лет назад

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2021-25741

почти 5 лет назад

A security issue was discovered in Kubernetes where a user may be able ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2021-25740

почти 5 лет назад

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

CVSS3: 3.1
EPSS: Низкий
redhat логотип

CVE-2021-25740

около 5 лет назад

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2021-25740

почти 5 лет назад

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-3294

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server's private network.

CVSS3: 6.6
2%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3294

Users may have access to secure endpoints in the control plane network ...

CVSS3: 6.6
2%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-3162

Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are true: 1. There are 2+ CustomResourceDefinitions sharing the same API group 2. Users have cluster-wide list or watch authorization on one of those custom resources. 3. The same users are not authorized to read another custom resource in the same API group.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-3162

Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are true: 1. There are 2+ CustomResourceDefinitions sharing the same API group 2. Users have cluster-wide list or watch authorization on one of those custom resources. 3. The same users are not authorized to read another custom resource in the same API group.

CVSS3: 6.5
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-3162

Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are true: 1. There are 2+ CustomResourceDefinitions sharing the same API group 2. Users have cluster-wide list or watch authorization on one of those custom resources. 3. The same users are not authorized to read another custom resource in the same API group.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3162

Users authorized to list or watch one type of namespaced custom resour ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2021-25749

Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.

CVSS3: 3.8
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-25749

Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-25749

Windows workloads can run as ContainerAdministrator even when those wo ...

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2021-25743

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-25743

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-25743

kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

CVSS3: 3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-25743

kubectl does not neutralize escape, meta or control sequences containe ...

CVSS3: 3
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-25741

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

CVSS3: 8.8
8%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-25741

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

CVSS3: 8.8
8%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-25741

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

CVSS3: 8.8
8%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-25741

A security issue was discovered in Kubernetes where a user may be able ...

CVSS3: 8.8
8%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-25740

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

CVSS3: 3.1
2%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-25740

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

CVSS3: 3.1
2%
Низкий
около 5 лет назад
nvd логотип
CVE-2021-25740

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

CVSS3: 3.1
2%
Низкий
почти 5 лет назад

Уязвимостей на страницу