Логотип exploitDog
bind:"CVE-2020-13379" OR bind:"CVE-2020-8555" OR bind:"CVE-2020-10749"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2020-13379" OR bind:"CVE-2020-8555" OR bind:"CVE-2020-10749"

Количество 30

Количество 30

oracle-oval логотип

ELSA-2020-5726

около 5 лет назад

ELSA-2020-5726: grafana kubernetes-cni kubernetes-cni-plugins kubernetes kubernetes olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5727

около 5 лет назад

ELSA-2020-5727: kubernetes-cni-plugins kubernetes-cni kubernetes olcne security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5725

около 5 лет назад

ELSA-2020-5725: kubernetes kubeadm-ha-setup kubernetes-cni kubernetes-cni-plugins security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2020-13379

около 5 лет назад

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

CVSS3: 8.2
EPSS: Критический
redhat логотип

CVE-2020-13379

около 5 лет назад

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

CVSS3: 8.2
EPSS: Критический
nvd логотип

CVE-2020-13379

около 5 лет назад

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

CVSS3: 8.2
EPSS: Критический
debian логотип

CVE-2020-13379

около 5 лет назад

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrec ...

CVSS3: 8.2
EPSS: Критический
github логотип

GHSA-wc9w-wvq2-ffm9

больше 3 лет назад

Server Side Request Forgery in Grafana

CVSS3: 5.8
EPSS: Критический
oracle-oval логотип

ELSA-2020-2641

почти 5 лет назад

ELSA-2020-2641: grafana security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2021-02136

около 5 лет назад

Уязвимость веб-инструмента представления данных Grafana, связанная с серверной фальсификацией запросов, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или вызвать отказ в обслуживании

CVSS3: 8.2
EPSS: Критический
ubuntu логотип

CVE-2020-8555

около 5 лет назад

The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback services).

CVSS3: 6.3
EPSS: Средний
redhat логотип

CVE-2020-8555

около 5 лет назад

The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback services).

CVSS3: 6.3
EPSS: Средний
nvd логотип

CVE-2020-8555

около 5 лет назад

The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback services).

CVSS3: 6.3
EPSS: Средний
debian логотип

CVE-2020-8555

около 5 лет назад

The Kubernetes kube-controller-manager in versions v1.0-1.14, versions ...

CVSS3: 6.3
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2020:0892-1

почти 5 лет назад

Security update for grafana, grafana-piechart-panel, grafana-status-panel

EPSS: Низкий
ubuntu логотип

CVE-2020-10749

около 5 лет назад

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
EPSS: Низкий
redhat логотип

CVE-2020-10749

около 5 лет назад

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
EPSS: Низкий
nvd логотип

CVE-2020-10749

около 5 лет назад

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
EPSS: Низкий
debian логотип

CVE-2020-10749

около 5 лет назад

A vulnerability was found in all versions of containernetworking/plugi ...

CVSS3: 6
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1105-1

почти 5 лет назад

Security update for SUSE Manager Client Tools

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2020-5726

ELSA-2020-5726: grafana kubernetes-cni kubernetes-cni-plugins kubernetes kubernetes olcne security update (IMPORTANT)

около 5 лет назад
oracle-oval логотип
ELSA-2020-5727

ELSA-2020-5727: kubernetes-cni-plugins kubernetes-cni kubernetes olcne security update (IMPORTANT)

около 5 лет назад
oracle-oval логотип
ELSA-2020-5725

ELSA-2020-5725: kubernetes kubeadm-ha-setup kubernetes-cni kubernetes-cni-plugins security update (IMPORTANT)

около 5 лет назад
ubuntu логотип
CVE-2020-13379

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

CVSS3: 8.2
93%
Критический
около 5 лет назад
redhat логотип
CVE-2020-13379

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

CVSS3: 8.2
93%
Критический
около 5 лет назад
nvd логотип
CVE-2020-13379

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.

CVSS3: 8.2
93%
Критический
около 5 лет назад
debian логотип
CVE-2020-13379

The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrec ...

CVSS3: 8.2
93%
Критический
около 5 лет назад
github логотип
GHSA-wc9w-wvq2-ffm9

Server Side Request Forgery in Grafana

CVSS3: 5.8
93%
Критический
больше 3 лет назад
oracle-oval логотип
ELSA-2020-2641

ELSA-2020-2641: grafana security update (IMPORTANT)

почти 5 лет назад
fstec логотип
BDU:2021-02136

Уязвимость веб-инструмента представления данных Grafana, связанная с серверной фальсификацией запросов, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или вызвать отказ в обслуживании

CVSS3: 8.2
93%
Критический
около 5 лет назад
ubuntu логотип
CVE-2020-8555

The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback services).

CVSS3: 6.3
14%
Средний
около 5 лет назад
redhat логотип
CVE-2020-8555

The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback services).

CVSS3: 6.3
14%
Средний
около 5 лет назад
nvd логотип
CVE-2020-8555

The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback services).

CVSS3: 6.3
14%
Средний
около 5 лет назад
debian логотип
CVE-2020-8555

The Kubernetes kube-controller-manager in versions v1.0-1.14, versions ...

CVSS3: 6.3
14%
Средний
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0892-1

Security update for grafana, grafana-piechart-panel, grafana-status-panel

почти 5 лет назад
ubuntu логотип
CVE-2020-10749

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
4%
Низкий
около 5 лет назад
redhat логотип
CVE-2020-10749

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
4%
Низкий
около 5 лет назад
nvd логотип
CVE-2020-10749

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.

CVSS3: 6
4%
Низкий
около 5 лет назад
debian логотип
CVE-2020-10749

A vulnerability was found in all versions of containernetworking/plugi ...

CVSS3: 6
4%
Низкий
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1105-1

Security update for SUSE Manager Client Tools

почти 5 лет назад

Уязвимостей на страницу