fluxcd records
7 published records for vendor fluxcd.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-1284 Improper Validation of Specified Quantity in Input1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-24817No exploit | Improper kubeconfig validation allows arbitrary code executionfluxcd · flux2 · CWE-94 | Critical9.9 | — | 1.1% | May 5, 2022 |
36Monitor | CVE-2021-41254No exploit | Privilege escalation to cluster admin on multi-tenant environmentsfluxcd · kustomize-controller · CWE-78 | High8.8 | — | 1.8% | Nov 12, 2021 |
35Monitor | CVE-2022-24877No exploit | Improper path handling in kustomization files allows path traversalfluxcd · flux2 · CWE-22 | High8.8 | — | 1.2% | May 5, 2022 |
31Monitor | CVE-2022-36035No exploit | Flux CLI Workload Injectionfluxcd · flux2 · CWE-22 | High7.8 | — | 0.3% | Aug 31, 2022 |
30Monitor | CVE-2022-36049No exploit | Flux2 Helm Controller denial of servicehelm · helm · CWE-400 | High7.5 | — | 1.4% | Sep 7, 2022 |
26Monitor | CVE-2022-24878No exploit | Improper path handling in Kustomization files allows for denial of servicefluxcd · flux2 · CWE-22 | Medium6.5 | — | 1.0% | May 5, 2022 |
17Monitor | CVE-2022-39272No exploit | Flux2 vulnerable to Denial of Service due to Improper use of metav1.Durationfluxcd · flux2 · CWE-1284 | Medium4.3 | — | 0.7% | Oct 21, 2022 |
- CVE-2022-2481739Monitor
Improper kubeconfig validation allows arbitrary code execution
CriticalCVSS 9.9No exploitEPSS 1%fluxcd · flux2May 5, 2022
- CVE-2021-4125436Monitor
Privilege escalation to cluster admin on multi-tenant environments
HighCVSS 8.8No exploitEPSS 2%fluxcd · kustomize-controllerNov 12, 2021
- CVE-2022-2487735Monitor
Improper path handling in kustomization files allows path traversal
HighCVSS 8.8No exploitEPSS 1%fluxcd · flux2May 5, 2022
- CVE-2022-3603531Monitor
Flux CLI Workload Injection
HighCVSS 7.8No exploitEPSS 0%fluxcd · flux2Aug 31, 2022
- CVE-2022-3604930Monitor
Flux2 Helm Controller denial of service
HighCVSS 7.5No exploitEPSS 1%helm · helmSep 7, 2022
- CVE-2022-2487826Monitor
Improper path handling in Kustomization files allows for denial of service
MediumCVSS 6.5No exploitEPSS 1%fluxcd · flux2May 5, 2022
- CVE-2022-3927217Monitor
Flux2 vulnerable to Denial of Service due to Improper use of metav1.Duration
MediumCVSS 4.3No exploitEPSS 1%fluxcd · flux2Oct 21, 2022