Записи weave
10 опубликованных записей вендора weave.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-284 Improper Access Control1
- CWE-306 Missing Authentication for Critical Function1
- CWE-350 Reliance on Reverse DNS Resolution for a Security-Critical Action1
- CWE-358 Improperly Implemented Security Check for Standard1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-35464Эксплойта нет | Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user.weave · cloud agent · CWE-306 | Критическая9,8 | — | 2,1 % | 15 дек. 2020 г. |
39Наблюдать | CVE-2022-35975Эксплойта нет | Improper object validation allows for arbitrary code execution in GitOps Tools Extension for VSCodeweave · gitops tools · CWE-78 | Критическая9,8 | — | 1,3 % | 18 авг. 2022 г. |
39Наблюдать | CVE-2022-35976Эксплойта нет | Improper KubeConfig handling allows arbitrary code executionweave · gitops tools · CWE-78 | Критическая9,8 | — | 0,5 % | 18 авг. 2022 г. |
32Наблюдать | CVE-2020-26278Эксплойта нет | Weave Net Pods running in host PID namespace can be used to escalate other Kubernetes vulnerabilitiesweave · weave · CWE-250 | Высокая8,0 | — | 0,7 % | 20 янв. 2021 г. |
31Наблюдать | CVE-2022-23508Эксплойта нет | GitOps Run allows for Kubernetes workload injectionweave · weave gitops · CWE-284 | Высокая7,8 | — | 0,3 % | 9 янв. 2023 г. |
31Наблюдать | CVE-2024-25545Эксплойта нет | An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework compoweave · weave desktop · CWE-358 | Высокая7,8 | — | 0,2 % | 12 апр. 2024 г. |
30Наблюдать | CVE-2022-31098Эксплойта нет | Weave GitOps leaked cluster credentials into logs on connection errorsweave · weave gitops · CWE-532 | Высокая7,5 | — | 1,2 % | 27 июн. 2022 г. |
26Наблюдать | CVE-2023-34236Эксплойта нет | Information Disclosure Vulnerability in Weave GitOps Terraform Controllerweave · gitops terraform controller · CWE-200 | Средняя6,5 | — | 1,0 % | 14 июл. 2023 г. |
24Наблюдать | CVE-2022-23509Эксплойта нет | Weave Gitops Run vulnerable to insecure communicationweave · weave gitops · CWE-200 | Средняя6,0 | — | 0,2 % | 9 янв. 2023 г. |
23Наблюдать | CVE-2020-11091Эксплойта нет | Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisementsweave · weave net · CWE-350 | Средняя5,8 | — | 0,9 % | 3 июн. 2020 г. |
- CVE-2020-3546440В плане
Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %weave · cloud agent15 дек. 2020 г.
- CVE-2022-3597539Наблюдать
Improper object validation allows for arbitrary code execution in GitOps Tools Extension for VSCode
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %weave · gitops tools18 авг. 2022 г.
- CVE-2022-3597639Наблюдать
Improper KubeConfig handling allows arbitrary code execution
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %weave · gitops tools18 авг. 2022 г.
- CVE-2020-2627832Наблюдать
Weave Net Pods running in host PID namespace can be used to escalate other Kubernetes vulnerabilities
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %weave · weave20 янв. 2021 г.
- CVE-2022-2350831Наблюдать
GitOps Run allows for Kubernetes workload injection
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %weave · weave gitops9 янв. 2023 г.
- CVE-2024-2554531Наблюдать
An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework compo
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %weave · weave desktop12 апр. 2024 г.
- CVE-2022-3109830Наблюдать
Weave GitOps leaked cluster credentials into logs on connection errors
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %weave · weave gitops27 июн. 2022 г.
- CVE-2023-3423626Наблюдать
Information Disclosure Vulnerability in Weave GitOps Terraform Controller
СредняяCVSS 6,5Эксплойта нетEPSS 1 %weave · gitops terraform controller14 июл. 2023 г.
- CVE-2022-2350924Наблюдать
Weave Gitops Run vulnerable to insecure communication
СредняяCVSS 6,0Эксплойта нетEPSS 0 %weave · weave gitops9 янв. 2023 г.
- CVE-2020-1109123Наблюдать
Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
СредняяCVSS 5,8Эксплойта нетEPSS 1 %weave · weave net3 июн. 2020 г.