Skip to content
Noroxi

weave records

10 published records for vendor weave.

All records

10 records
  • Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user.

    CriticalCVSS 9.8No exploitEPSS 2%

    weave · cloud agentDec 15, 2020

  • Improper object validation allows for arbitrary code execution in GitOps Tools Extension for VSCode

    CriticalCVSS 9.8No exploitEPSS 1%

    weave · gitops toolsAug 18, 2022

  • Improper KubeConfig handling allows arbitrary code execution

    CriticalCVSS 9.8No exploitEPSS 1%

    weave · gitops toolsAug 18, 2022

  • Weave Net Pods running in host PID namespace can be used to escalate other Kubernetes vulnerabilities

    HighCVSS 8.0No exploitEPSS 1%

    weave · weaveJan 20, 2021

  • GitOps Run allows for Kubernetes workload injection

    HighCVSS 7.8No exploitEPSS 0%

    weave · weave gitopsJan 9, 2023

  • An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework compo

    HighCVSS 7.8No exploitEPSS 0%

    weave · weave desktopApr 12, 2024

  • Weave GitOps leaked cluster credentials into logs on connection errors

    HighCVSS 7.5No exploitEPSS 1%

    weave · weave gitopsJun 27, 2022

  • Information Disclosure Vulnerability in Weave GitOps Terraform Controller

    MediumCVSS 6.5No exploitEPSS 1%

    weave · gitops terraform controllerJul 14, 2023

  • Weave Gitops Run vulnerable to insecure communication

    MediumCVSS 6.0No exploitEPSS 0%

    weave · weave gitopsJan 9, 2023

  • Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements

    MediumCVSS 5.8No exploitEPSS 1%

    weave · weave netJun 3, 2020