CVEs (11)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Kubernetes Netapp2Ingress Nginx TridentJun 17, 2026 Oct 29, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster. |
4Fedoraproject GolangNetapp+1 more6Cloud Insights Telegraf FedoraGo+3 moreJun 17, 2026 Jul 15, 2021 N/A· v4 6.5 MEDIUM· v3 2.6 LOW· v2 The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to c...Show more |
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting w...Show more |
The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting ways d...Show more |
The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that behave in conflicting...Show more |
3Fedoraproject GolangNetapp4Cloud Insights Telegraf Agent FedoraGo+1 moreJun 17, 2026 Nov 18, 2020 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file. |
3Fedoraproject GolangNetapp4Cloud Insights Telegraf Agent FedoraGo+1 moreJun 17, 2026 Nov 18, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service. |
13Apache AppleCanonical+10 more28Big Ip Local Traffic Manager Cloud InsightsDebian Linux+25 moreJun 17, 2026 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream o...Show more |
3Kubernetes NetappRedhat3Kubernetes Openshift Container PlatformTridentJun 17, 2026 Apr 22, 2019 N/A· v4 5.0 MEDIUM· v3 1.9 LOW· v2 In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is spec...Show more |
2Kubernetes Netapp2Kubernetes TridentJun 17, 2026 Apr 22, 2019 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In th...Show more |
3Kubernetes NetappRedhat3Kubernetes Openshift Container PlatformTridentNov 21, 2024 Dec 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection thr...Show more |