weave records
10 published records for vendor weave.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-284 Improper Access Control1
- CWE-306 Missing Authentication for Critical Function1
- CWE-350 Reliance on Reverse DNS Resolution for a Security-Critical Action1
- CWE-358 Improperly Implemented Security Check for Standard1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-35464No exploit | Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user.weave · cloud agent · CWE-306 | Critical9.8 | — | 2.1% | Dec 15, 2020 |
39Monitor | CVE-2022-35975No exploit | Improper object validation allows for arbitrary code execution in GitOps Tools Extension for VSCodeweave · gitops tools · CWE-78 | Critical9.8 | — | 1.3% | Aug 18, 2022 |
39Monitor | CVE-2022-35976No exploit | Improper KubeConfig handling allows arbitrary code executionweave · gitops tools · CWE-78 | Critical9.8 | — | 0.5% | Aug 18, 2022 |
32Monitor | CVE-2020-26278No exploit | Weave Net Pods running in host PID namespace can be used to escalate other Kubernetes vulnerabilitiesweave · weave · CWE-250 | High8.0 | — | 0.7% | Jan 20, 2021 |
31Monitor | CVE-2022-23508No exploit | GitOps Run allows for Kubernetes workload injectionweave · weave gitops · CWE-284 | High7.8 | — | 0.3% | Jan 9, 2023 |
31Monitor | CVE-2024-25545No exploit | An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework compoweave · weave desktop · CWE-358 | High7.8 | — | 0.2% | Apr 12, 2024 |
30Monitor | CVE-2022-31098No exploit | Weave GitOps leaked cluster credentials into logs on connection errorsweave · weave gitops · CWE-532 | High7.5 | — | 1.2% | Jun 27, 2022 |
26Monitor | CVE-2023-34236No exploit | Information Disclosure Vulnerability in Weave GitOps Terraform Controllerweave · gitops terraform controller · CWE-200 | Medium6.5 | — | 1.0% | Jul 14, 2023 |
24Monitor | CVE-2022-23509No exploit | Weave Gitops Run vulnerable to insecure communicationweave · weave gitops · CWE-200 | Medium6.0 | — | 0.2% | Jan 9, 2023 |
23Monitor | CVE-2020-11091No exploit | Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisementsweave · weave net · CWE-350 | Medium5.8 | — | 0.9% | Jun 3, 2020 |
- CVE-2020-3546440Plan
Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user.
CriticalCVSS 9.8No exploitEPSS 2%weave · cloud agentDec 15, 2020
- CVE-2022-3597539Monitor
Improper object validation allows for arbitrary code execution in GitOps Tools Extension for VSCode
CriticalCVSS 9.8No exploitEPSS 1%weave · gitops toolsAug 18, 2022
- CVE-2022-3597639Monitor
Improper KubeConfig handling allows arbitrary code execution
CriticalCVSS 9.8No exploitEPSS 1%weave · gitops toolsAug 18, 2022
- CVE-2020-2627832Monitor
Weave Net Pods running in host PID namespace can be used to escalate other Kubernetes vulnerabilities
HighCVSS 8.0No exploitEPSS 1%weave · weaveJan 20, 2021
- CVE-2022-2350831Monitor
GitOps Run allows for Kubernetes workload injection
HighCVSS 7.8No exploitEPSS 0%weave · weave gitopsJan 9, 2023
- CVE-2024-2554531Monitor
An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework compo
HighCVSS 7.8No exploitEPSS 0%weave · weave desktopApr 12, 2024
- CVE-2022-3109830Monitor
Weave GitOps leaked cluster credentials into logs on connection errors
HighCVSS 7.5No exploitEPSS 1%weave · weave gitopsJun 27, 2022
- CVE-2023-3423626Monitor
Information Disclosure Vulnerability in Weave GitOps Terraform Controller
MediumCVSS 6.5No exploitEPSS 1%weave · gitops terraform controllerJul 14, 2023
- CVE-2022-2350924Monitor
Weave Gitops Run vulnerable to insecure communication
MediumCVSS 6.0No exploitEPSS 0%weave · weave gitopsJan 9, 2023
- CVE-2020-1109123Monitor
Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
MediumCVSS 5.8No exploitEPSS 1%weave · weave netJun 3, 2020