Skip to content
Noroxi

cncf records

8 published records for vendor cncf.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
87.5%
Median publish → KEV
No record has entered KEV

All records

8 records
  • Crossplane vulnerable to possible image tampering from missing image validation for Packages

    CriticalCVSS 9.8No exploitEPSS 1%

    cncf · crossplaneJul 27, 2023

  • In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SP

    HighCVSS 8.1No exploitEPSS 1%

    cncf · spireMar 5, 2021

  • CVE-2019-9946
    31Monitor

    Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Ku

    HighCVSS 7.5No exploitEPSS 3%

    cncf · portmapApr 2, 2019

  • CVE-2020-8659
    31Monitor

    CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e.

    HighCVSS 7.5No exploitEPSS 2%

    cncf · envoyMar 4, 2020

  • CVE-2020-8661
    31Monitor

    CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.

    HighCVSS 7.5No exploitEPSS 2%

    cncf · envoyMar 4, 2020

  • In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided throug

    MediumCVSS 6.8No exploitEPSS 1%

    cncf · spireMar 5, 2021

  • CVE-2020-8664
    21Monitor

    CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context.

    MediumCVSS 5.3No exploitEPSS 1%

    cncf · envoyMar 4, 2020

  • Crossplane vulnerable to denial of service from large image

    LowCVSS 2.7No exploitEPSS 1%

    cncf · crossplaneJul 27, 2023