Kubernetes
kubernetes
93 CVEs • 18 products
Products (18)
Click to collapseToggle
Products (18)
Click to collapse
CVEs (93)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
This vulnerability enables ssh access to minikube container using a default password. |
This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container. |
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true. |
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress o...Show more |
Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxyin...Show more |
Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability...Show more |
Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where s...Show more |
1Kubernetes 1Aws Iam Authenticator Jun 17, 2026 Jul 12, 2022 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges. |
3Fedoraproject KubernetesRedhat4Cri O Enterprise LinuxFedora+1 moreJun 17, 2026 Jun 7, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. Thi...Show more |
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the...Show more |
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API gr...Show more |
4Fedoraproject KubernetesMobyproject+1 more4Cri O FedoraMoby+1 moreJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable L...Show more |
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary c...Show more |
2Kubernetes Redhat2Cri O Openshift Container PlatformJun 17, 2026 Feb 9, 2022 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod...Show more |
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or...Show more |
kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events. |
2Kubernetes Netapp2Ingress Nginx TridentJun 17, 2026 Oct 29, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster. |
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. |
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem. |
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. |