Записи fluxcd
7 опубликованных записей вендора fluxcd.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-1284 Improper Validation of Specified Quantity in Input1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2022-24817Эксплойта нет | Improper kubeconfig validation allows arbitrary code executionfluxcd · flux2 · CWE-94 | Критическая9,9 | — | 1,1 % | 5 мая 2022 г. |
36Наблюдать | CVE-2021-41254Эксплойта нет | Privilege escalation to cluster admin on multi-tenant environmentsfluxcd · kustomize-controller · CWE-78 | Высокая8,8 | — | 1,8 % | 12 нояб. 2021 г. |
35Наблюдать | CVE-2022-24877Эксплойта нет | Improper path handling in kustomization files allows path traversalfluxcd · flux2 · CWE-22 | Высокая8,8 | — | 1,2 % | 5 мая 2022 г. |
31Наблюдать | CVE-2022-36035Эксплойта нет | Flux CLI Workload Injectionfluxcd · flux2 · CWE-22 | Высокая7,8 | — | 0,3 % | 31 авг. 2022 г. |
30Наблюдать | CVE-2022-36049Эксплойта нет | Flux2 Helm Controller denial of servicehelm · helm · CWE-400 | Высокая7,5 | — | 1,4 % | 7 сент. 2022 г. |
26Наблюдать | CVE-2022-24878Эксплойта нет | Improper path handling in Kustomization files allows for denial of servicefluxcd · flux2 · CWE-22 | Средняя6,5 | — | 1,0 % | 5 мая 2022 г. |
17Наблюдать | CVE-2022-39272Эксплойта нет | Flux2 vulnerable to Denial of Service due to Improper use of metav1.Durationfluxcd · flux2 · CWE-1284 | Средняя4,3 | — | 0,7 % | 21 окт. 2022 г. |
- CVE-2022-2481739Наблюдать
Improper kubeconfig validation allows arbitrary code execution
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %fluxcd · flux25 мая 2022 г.
- CVE-2021-4125436Наблюдать
Privilege escalation to cluster admin on multi-tenant environments
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %fluxcd · kustomize-controller12 нояб. 2021 г.
- CVE-2022-2487735Наблюдать
Improper path handling in kustomization files allows path traversal
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %fluxcd · flux25 мая 2022 г.
- CVE-2022-3603531Наблюдать
Flux CLI Workload Injection
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %fluxcd · flux231 авг. 2022 г.
- CVE-2022-3604930Наблюдать
Flux2 Helm Controller denial of service
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %helm · helm7 сент. 2022 г.
- CVE-2022-2487826Наблюдать
Improper path handling in Kustomization files allows for denial of service
СредняяCVSS 6,5Эксплойта нетEPSS 1 %fluxcd · flux25 мая 2022 г.
- CVE-2022-3927217Наблюдать
Flux2 vulnerable to Denial of Service due to Improper use of metav1.Duration
СредняяCVSS 4,3Эксплойта нетEPSS 1 %fluxcd · flux221 окт. 2022 г.