Записи cncf
8 опубликованных записей вендора cncf.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 87,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption2
- CWE-287 Improper Authentication1
- CWE-295 Improper Certificate Validation1
- CWE-20 Improper Input Validation1
- CWE-670 Always-Incorrect Control Flow Implementation1
- CWE-770 Allocation of Resources Without Limits or Throttling1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-38495Эксплойта нет | Crossplane vulnerable to possible image tampering from missing image validation for Packagescncf · crossplane · CWE-20 | Критическая9,8 | — | 0,8 % | 27 июл. 2023 г. |
32Наблюдать | CVE-2021-27098Эксплойта нет | In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPcncf · spire · CWE-295 | Высокая8,1 | — | 0,6 % | 5 мар. 2021 г. |
31Наблюдать | CVE-2019-9946Эксплойта нет | Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kucncf · portmap · CWE-670 | Высокая7,5 | — | 3,2 % | 2 апр. 2019 г. |
31Наблюдать | CVE-2020-8659Эксплойта нет | CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e.cncf · envoy · CWE-770 | Высокая7,5 | — | 1,9 % | 4 мар. 2020 г. |
31Наблюдать | CVE-2020-8661Эксплойта нет | CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.cncf · envoy · CWE-400 | Высокая7,5 | — | 1,9 % | 4 мар. 2020 г. |
27Наблюдать | CVE-2021-27099Эксплойта нет | In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided througcncf · spire · CWE-863 | Средняя6,8 | — | 0,7 % | 5 мар. 2021 г. |
21Наблюдать | CVE-2020-8664Эксплойта нет | CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context.cncf · envoy · CWE-287 | Средняя5,3 | — | 1,3 % | 4 мар. 2020 г. |
10Наблюдать | CVE-2023-37900Эксплойта нет | Crossplane vulnerable to denial of service from large imagecncf · crossplane · CWE-400 | Низкая2,7 | — | 0,6 % | 27 июл. 2023 г. |
- CVE-2023-3849539Наблюдать
Crossplane vulnerable to possible image tampering from missing image validation for Packages
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cncf · crossplane27 июл. 2023 г.
- CVE-2021-2709832Наблюдать
In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SP
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %cncf · spire5 мар. 2021 г.
- CVE-2019-994631Наблюдать
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Ku
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %cncf · portmap2 апр. 2019 г.
- CVE-2020-865931Наблюдать
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %cncf · envoy4 мар. 2020 г.
- CVE-2020-866131Наблюдать
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %cncf · envoy4 мар. 2020 г.
- CVE-2021-2709927Наблюдать
In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided throug
СредняяCVSS 6,8Эксплойта нетEPSS 1 %cncf · spire5 мар. 2021 г.
- CVE-2020-866421Наблюдать
CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %cncf · envoy4 мар. 2020 г.
- CVE-2023-3790010Наблюдать
Crossplane vulnerable to denial of service from large image
НизкаяCVSS 2,7Эксплойта нетEPSS 1 %cncf · crossplane27 июл. 2023 г.