İçeriğe atla
Noroxi

cncf kayıtları

cncf üreticisine ait 8 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%87,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

8 kayıt
  • CVE-2023-38495
    39İzleyin

    Crossplane vulnerable to possible image tampering from missing image validation for Packages

    KritikCVSS 9,8İstismar yokEPSS %1

    cncf · crossplane27 Tem 2023

  • CVE-2021-27098
    32İzleyin

    In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SP

    YüksekCVSS 8,1İstismar yokEPSS %1

    cncf · spire5 Mar 2021

  • CVE-2019-9946
    31İzleyin

    Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Ku

    YüksekCVSS 7,5İstismar yokEPSS %3

    cncf · portmap2 Nis 2019

  • CVE-2020-8659
    31İzleyin

    CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e.

    YüksekCVSS 7,5İstismar yokEPSS %2

    cncf · envoy4 Mar 2020

  • CVE-2020-8661
    31İzleyin

    CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.

    YüksekCVSS 7,5İstismar yokEPSS %2

    cncf · envoy4 Mar 2020

  • CVE-2021-27099
    27İzleyin

    In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided throug

    OrtaCVSS 6,8İstismar yokEPSS %1

    cncf · spire5 Mar 2021

  • CVE-2020-8664
    21İzleyin

    CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context.

    OrtaCVSS 5,3İstismar yokEPSS %1

    cncf · envoy4 Mar 2020

  • CVE-2023-37900
    10İzleyin

    Crossplane vulnerable to denial of service from large image

    DüşükCVSS 2,7İstismar yokEPSS %1

    cncf · crossplane27 Tem 2023