Записи Kubernetes
102 опубликованных записей вендора kubernetes.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 90,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation26
- CWE-532 Insertion of Sensitive Information into Log File6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-61 UNIX Symbolic Link (Symlink) Following3
- CWE-284 Improper Access Control3
- CWE-266 Incorrect Privilege Assignment2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
102 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
65На этой неделе | CVE-2018-1002105Proof of concept | In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in thekubernetes · kubernetes · CWE-388 | Критическая9,8 | — | 87,0 % | 5 дек. 2018 г. |
55В плане | CVE-2019-11248Proof of concept | Kubernetes kubelet exposes /debug/pprof info on healthz portkubernetes · kubernetes · CWE-419 | Высокая8,2 | — | 75,1 % | 28 авг. 2019 г. |
52В плане | CVE-2023-5044Proof of concept | Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotationkubernetes · ingress-nginx · CWE-20 | Высокая8,8 | — | 56,6 % | 25 окт. 2023 г. |
51В плане | CVE-2018-18264Proof of concept | Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within kubernetes · dashboard · CWE-306 | Высокая7,5 | — | 70,4 % | 2 янв. 2019 г. |
43В плане | CVE-2024-7646Proof of concept | A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `exkubernetes · ingress-nginx · CWE-20 | Высокая8,8 | — | 27,0 % | 16 авг. 2024 г. |
42В плане | CVE-2017-1002101Proof of concept | In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with kubernetes · kubernetes · CWE-59 | Критическая9,6 | — | 12,9 % | 13 мар. 2018 г. |
41В плане | CVE-2022-0811Proof of concept | A flaw was found in CRI-O in the way it set kernel options for a pod.kubernetes · cri-o · CWE-94 | Высокая8,8 | — | 19,0 % | 16 мар. 2022 г. |
40В плане | CVE-2016-1906Эксплойта нет | Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that kubernetes · kubernetes · CWE-264 | Критическая9,8 | — | 4,8 % | 3 февр. 2016 г. |
40В плане | CVE-2018-1002101Эксплойта нет | In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Wikubernetes · kubernetes | Критическая9,8 | — | 4,0 % | 5 дек. 2018 г. |
40В плане | CVE-2017-1000056Эксплойта нет | Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability tokubernetes · kubernetes · CWE-862 | Критическая9,8 | — | 2,8 % | 17 июл. 2017 г. |
40В плане | CVE-2025-57870Эксплойта нет | BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services.esri · arcgis server · CWE-89 | Критическая10,0 | — | 0,5 % | 22 окт. 2025 г. |
39Наблюдать | CVE-2023-3676Эксплойта нет | Kubernetes - Windows nodes - Insufficient input sanitization leads to privilege escalationkubernetes · kubernetes · CWE-20 | Высокая8,8 | — | 13,2 % | 31 окт. 2023 г. |
39Наблюдать | CVE-2026-13019Эксплойта нет | Missing Authenticationesri · portal for arcgis · CWE-640 | Критическая9,8 | — | 0,8 % | 7 июл. 2026 г. |
39Наблюдать | CVE-2023-1174Эксплойта нет | [minikube] Network Port exposure in minikube running on macOS using Docker driverkubernetes · minikube · CWE-266 | Критическая9,8 | — | 0,8 % | 24 мая 2023 г. |
39Наблюдать | CVE-2026-33519Эксплойта нет | Incorrect privilege assignment in Portal for ArcGISesri · portal for arcgis · CWE-266 | Критическая9,8 | — | 0,5 % | 21 апр. 2026 г. |
39Наблюдать | CVE-2026-13020Эксплойта нет | Weak Password Recovery Mechanism in Portal for ArcGISesri · portal for arcgis · CWE-640 | Критическая9,8 | — | 0,5 % | 7 июл. 2026 г. |
38Наблюдать | CVE-2019-11253Proof of concept | Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attackkubernetes · kubernetes · CWE-20 | Высокая7,5 | — | 25,9 % | 17 окт. 2019 г. |
37Наблюдать | CVE-2020-8570Proof of concept | Kubernetes Java client libraries unvalidated path traversal in Copy implementationkubernetes · java · CWE-23 | Критическая9,1 | — | 3,6 % | 21 янв. 2021 г. |
36Наблюдать | CVE-2023-5528Эксплойта нет | Kubernetes - Windows nodes - Insufficient input sanitization in in-tree storage plugin leads to privilege escalationkubernetes · kubernetes · CWE-20 | Высокая8,8 | — | 4,3 % | 14 нояб. 2023 г. |
36Наблюдать | CVE-2023-3955Эксплойта нет | Kubernetes - Windows nodes - Insufficient input sanitization leads to privilege escalationkubernetes · kubernetes · CWE-20 | Высокая8,8 | — | 4,0 % | 31 окт. 2023 г. |
36Наблюдать | CVE-2020-8558Proof of concept | Kubernetes node setting allows for neighboring hosts to bypass localhost boundarykubernetes · kubernetes · CWE-420 | Высокая8,8 | — | 3,6 % | 27 июл. 2020 г. |
36Наблюдать | CVE-2023-3893Эксплойта нет | Kubernetes - csi-proxy - Insufficient input sanitization leads to privilege escalationkubernetes · csi proxy · CWE-20 | Высокая8,8 | — | 2,5 % | 3 нояб. 2023 г. |
36Наблюдать | CVE-2023-5043Proof of concept | Ingress nginx annotation injection causes arbitrary command executionkubernetes · ingress-nginx · CWE-20 | Высокая8,8 | — | 2,2 % | 25 окт. 2023 г. |
36Наблюдать | CVE-2018-1000400Эксплойта нет | Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabikubernetes · cri-o · CWE-269 | Высокая8,8 | — | 2,0 % | 18 мая 2018 г. |
35Наблюдать | CVE-2022-3294Proof of concept | Node address isn't always verified when proxyingkubernetes · kubernetes · CWE-20 | Высокая8,8 | — | 1,6 % | 1 мар. 2023 г. |
- CVE-2018-100210565На этой неделе
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the
КритическаяCVSS 9,8Proof of conceptEPSS 87 %kubernetes · kubernetes5 дек. 2018 г.
- CVE-2019-1124855В плане
Kubernetes kubelet exposes /debug/pprof info on healthz port
ВысокаяCVSS 8,2Proof of conceptEPSS 75 %kubernetes · kubernetes28 авг. 2019 г.
- CVE-2023-504452В плане
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
ВысокаяCVSS 8,8Proof of conceptEPSS 57 %kubernetes · ingress-nginx25 окт. 2023 г.
- CVE-2018-1826451В плане
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within
ВысокаяCVSS 7,5Proof of conceptEPSS 70 %kubernetes · dashboard2 янв. 2019 г.
- CVE-2024-764643В плане
A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `ex
ВысокаяCVSS 8,8Proof of conceptEPSS 27 %kubernetes · ingress-nginx16 авг. 2024 г.
- CVE-2017-100210142В плане
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with
КритическаяCVSS 9,6Proof of conceptEPSS 13 %kubernetes · kubernetes13 мар. 2018 г.
- CVE-2022-081141В плане
A flaw was found in CRI-O in the way it set kernel options for a pod.
ВысокаяCVSS 8,8Proof of conceptEPSS 19 %kubernetes · cri-o16 мар. 2022 г.
- CVE-2016-190640В плане
Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %kubernetes · kubernetes3 февр. 2016 г.
- CVE-2018-100210140В плане
In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Wi
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %kubernetes · kubernetes5 дек. 2018 г.
- CVE-2017-100005640В плане
Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %kubernetes · kubernetes17 июл. 2017 г.
- CVE-2025-5787040В плане
BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %esri · arcgis server22 окт. 2025 г.
- CVE-2023-367639Наблюдать
Kubernetes - Windows nodes - Insufficient input sanitization leads to privilege escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 13 %kubernetes · kubernetes31 окт. 2023 г.
- CVE-2026-1301939Наблюдать
Missing Authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %esri · portal for arcgis7 июл. 2026 г.
- CVE-2023-117439Наблюдать
[minikube] Network Port exposure in minikube running on macOS using Docker driver
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %kubernetes · minikube24 мая 2023 г.
- CVE-2026-3351939Наблюдать
Incorrect privilege assignment in Portal for ArcGIS
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %esri · portal for arcgis21 апр. 2026 г.
- CVE-2026-1302039Наблюдать
Weak Password Recovery Mechanism in Portal for ArcGIS
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %esri · portal for arcgis7 июл. 2026 г.
- CVE-2019-1125338Наблюдать
Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
ВысокаяCVSS 7,5Proof of conceptEPSS 26 %kubernetes · kubernetes17 окт. 2019 г.
- CVE-2020-857037Наблюдать
Kubernetes Java client libraries unvalidated path traversal in Copy implementation
КритическаяCVSS 9,1Proof of conceptEPSS 4 %kubernetes · java21 янв. 2021 г.
- CVE-2023-552836Наблюдать
Kubernetes - Windows nodes - Insufficient input sanitization in in-tree storage plugin leads to privilege escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %kubernetes · kubernetes14 нояб. 2023 г.
- CVE-2023-395536Наблюдать
Kubernetes - Windows nodes - Insufficient input sanitization leads to privilege escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %kubernetes · kubernetes31 окт. 2023 г.
- CVE-2020-855836Наблюдать
Kubernetes node setting allows for neighboring hosts to bypass localhost boundary
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %kubernetes · kubernetes27 июл. 2020 г.
- CVE-2023-389336Наблюдать
Kubernetes - csi-proxy - Insufficient input sanitization leads to privilege escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %kubernetes · csi proxy3 нояб. 2023 г.
- CVE-2023-504336Наблюдать
Ingress nginx annotation injection causes arbitrary command execution
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %kubernetes · ingress-nginx25 окт. 2023 г.
- CVE-2018-100040036Наблюдать
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabi
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %kubernetes · cri-o18 мая 2018 г.
- CVE-2022-329435Наблюдать
Node address isn't always verified when proxying
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %kubernetes · kubernetes1 мар. 2023 г.