cncf records
8 published records for vendor cncf.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 87.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption2
- CWE-287 Improper Authentication1
- CWE-295 Improper Certificate Validation1
- CWE-20 Improper Input Validation1
- CWE-670 Always-Incorrect Control Flow Implementation1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-38495No exploit | Crossplane vulnerable to possible image tampering from missing image validation for Packagescncf · crossplane · CWE-20 | Critical9.8 | — | 0.8% | Jul 27, 2023 |
32Monitor | CVE-2021-27098No exploit | In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPcncf · spire · CWE-295 | High8.1 | — | 0.6% | Mar 5, 2021 |
31Monitor | CVE-2019-9946No exploit | Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kucncf · portmap · CWE-670 | High7.5 | — | 3.2% | Apr 2, 2019 |
31Monitor | CVE-2020-8659No exploit | CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e.cncf · envoy · CWE-770 | High7.5 | — | 1.9% | Mar 4, 2020 |
31Monitor | CVE-2020-8661No exploit | CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.cncf · envoy · CWE-400 | High7.5 | — | 1.9% | Mar 4, 2020 |
27Monitor | CVE-2021-27099No exploit | In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided througcncf · spire · CWE-863 | Medium6.8 | — | 0.7% | Mar 5, 2021 |
21Monitor | CVE-2020-8664No exploit | CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context.cncf · envoy · CWE-287 | Medium5.3 | — | 1.3% | Mar 4, 2020 |
10Monitor | CVE-2023-37900No exploit | Crossplane vulnerable to denial of service from large imagecncf · crossplane · CWE-400 | Low2.7 | — | 0.6% | Jul 27, 2023 |
- CVE-2023-3849539Monitor
Crossplane vulnerable to possible image tampering from missing image validation for Packages
CriticalCVSS 9.8No exploitEPSS 1%cncf · crossplaneJul 27, 2023
- CVE-2021-2709832Monitor
In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SP
HighCVSS 8.1No exploitEPSS 1%cncf · spireMar 5, 2021
- CVE-2019-994631Monitor
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Ku
HighCVSS 7.5No exploitEPSS 3%cncf · portmapApr 2, 2019
- CVE-2020-865931Monitor
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e.
HighCVSS 7.5No exploitEPSS 2%cncf · envoyMar 4, 2020
- CVE-2020-866131Monitor
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.
HighCVSS 7.5No exploitEPSS 2%cncf · envoyMar 4, 2020
- CVE-2021-2709927Monitor
In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided throug
MediumCVSS 6.8No exploitEPSS 1%cncf · spireMar 5, 2021
- CVE-2020-866421Monitor
CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context.
MediumCVSS 5.3No exploitEPSS 1%cncf · envoyMar 4, 2020
- CVE-2023-3790010Monitor
Crossplane vulnerable to denial of service from large image
LowCVSS 2.7No exploitEPSS 1%cncf · crossplaneJul 27, 2023