Mirantis records
5 published records for vendor mirantis.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-284 Improper Access Control1
- CWE-287 Improper Authentication1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2021-44458No exploit | Lack of websocket authentication in Lens causes remote code execution when visiting a malicious websitelinux · linux kernel · CWE-287 | Critical9.6 | — | 0.4% | Jan 10, 2022 |
35Monitor | CVE-2022-0484No exploit | Improper URL Validation causes Mirantis Container Cloud Lens Extension to open external programsmirantis · container cloud lens extension · CWE-20 | High8.8 | — | 1.0% | Feb 4, 2022 |
35Monitor | CVE-2022-0270No exploit | Improper header sanitization in bored-agent causes escalation of privilegemirantis · bored-agent · CWE-284 | High8.8 | — | 0.9% | Jan 25, 2022 |
31Monitor | CVE-2021-23154No exploit | Command injection in Lens causes arbitrary shell command execution when malicious custom helm chart configuration providedmirantis · lens · CWE-94 | High7.8 | — | 0.6% | Jan 10, 2022 |
30Monitor | CVE-2021-23218No exploit | Memory Leak in Mirantis Container Runtime (MCR) running in FIPS mode causes a Denial of Servicemirantis · mirantis container runtime · CWE-401 | High7.5 | — | 0.9% | Jan 10, 2022 |
- CVE-2021-4445838Monitor
Lack of websocket authentication in Lens causes remote code execution when visiting a malicious website
CriticalCVSS 9.6No exploitEPSS 0%linux · linux kernelJan 10, 2022
- CVE-2022-048435Monitor
Improper URL Validation causes Mirantis Container Cloud Lens Extension to open external programs
HighCVSS 8.8No exploitEPSS 1%mirantis · container cloud lens extensionFeb 4, 2022
- CVE-2022-027035Monitor
Improper header sanitization in bored-agent causes escalation of privilege
HighCVSS 8.8No exploitEPSS 1%mirantis · bored-agentJan 25, 2022
- CVE-2021-2315431Monitor
Command injection in Lens causes arbitrary shell command execution when malicious custom helm chart configuration provided
HighCVSS 7.8No exploitEPSS 1%mirantis · lensJan 10, 2022
- CVE-2021-2321830Monitor
Memory Leak in Mirantis Container Runtime (MCR) running in FIPS mode causes a Denial of Service
HighCVSS 7.5No exploitEPSS 1%mirantis · mirantis container runtimeJan 10, 2022