Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

github логотип

GHSA-pxhw-596r-rwq5

больше 2 лет назад

Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

CVSS3: 2.7
EPSS: Низкий
ubuntu логотип

CVE-2024-3177

больше 2 лет назад

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

CVSS3: 2.7
EPSS: Низкий
redhat логотип

CVE-2024-3177

больше 2 лет назад

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2024-3177

больше 2 лет назад

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

CVSS3: 2.7
EPSS: Низкий
msrc логотип

CVE-2024-3177

6 месяцев назад

Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2024-3177

больше 2 лет назад

A security issue was discovered in Kubernetes where users may be able ...

CVSS3: 2.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1404-1

больше 2 лет назад

Security update for kubernetes1.23

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1403-1

больше 2 лет назад

Security update for kubernetes1.24

EPSS: Низкий
fstec логотип

BDU:2024-04110

больше 2 лет назад

Уязвимость компонента KUBE-APISERVER программного средства управления кластерами виртуальных машин Kubernetes, позволяющая нарушителю запускать контейнеры в обход политики безопасности

CVSS3: 2.7
EPSS: Низкий
redos логотип

ROS-20240522-03

около 2 лет назад

Уязвимость kubernetes

CVSS3: 2.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02423-2

около 1 года назад

Security update for kubernetes1.23

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3343-1

почти 2 года назад

Security update for kubernetes1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3341-1

почти 2 года назад

Security update for kubernetes1.23

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-pxhw-596r-rwq5

Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

CVSS3: 2.7
2%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-3177

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

CVSS3: 2.7
2%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-3177

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

CVSS3: 2.7
2%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-3177

A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.

CVSS3: 2.7
2%
Низкий
больше 2 лет назад
msrc логотип
CVE-2024-3177

Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

CVSS3: 2.7
2%
Низкий
6 месяцев назад
debian логотип
CVE-2024-3177

A security issue was discovered in Kubernetes where users may be able ...

CVSS3: 2.7
2%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1404-1

Security update for kubernetes1.23

2%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:1403-1

Security update for kubernetes1.24

2%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-04110

Уязвимость компонента KUBE-APISERVER программного средства управления кластерами виртуальных машин Kubernetes, позволяющая нарушителю запускать контейнеры в обход политики безопасности

CVSS3: 2.7
2%
Низкий
больше 2 лет назад
redos логотип
ROS-20240522-03

Уязвимость kubernetes

CVSS3: 2.7
2%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2025:02423-2

Security update for kubernetes1.23

около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3343-1

Security update for kubernetes1.24

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:3341-1

Security update for kubernetes1.23

почти 2 года назад

Уязвимостей на страницу