cncf kayıtları
cncf üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %87,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption2
- CWE-287 Improper Authentication1
- CWE-295 Improper Certificate Validation1
- CWE-20 Improper Input Validation1
- CWE-670 Always-Incorrect Control Flow Implementation1
- CWE-770 Allocation of Resources Without Limits or Throttling1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-38495İstismar yok | Crossplane vulnerable to possible image tampering from missing image validation for Packagescncf · crossplane · CWE-20 | Kritik9,8 | — | %0,8 | 27 Tem 2023 |
32İzleyin | CVE-2021-27098İstismar yok | In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPcncf · spire · CWE-295 | Yüksek8,1 | — | %0,6 | 5 Mar 2021 |
31İzleyin | CVE-2019-9946İstismar yok | Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kucncf · portmap · CWE-670 | Yüksek7,5 | — | %3,2 | 2 Nis 2019 |
31İzleyin | CVE-2020-8659İstismar yok | CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e.cncf · envoy · CWE-770 | Yüksek7,5 | — | %1,9 | 4 Mar 2020 |
31İzleyin | CVE-2020-8661İstismar yok | CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.cncf · envoy · CWE-400 | Yüksek7,5 | — | %1,9 | 4 Mar 2020 |
27İzleyin | CVE-2021-27099İstismar yok | In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided througcncf · spire · CWE-863 | Orta6,8 | — | %0,7 | 5 Mar 2021 |
21İzleyin | CVE-2020-8664İstismar yok | CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context.cncf · envoy · CWE-287 | Orta5,3 | — | %1,3 | 4 Mar 2020 |
10İzleyin | CVE-2023-37900İstismar yok | Crossplane vulnerable to denial of service from large imagecncf · crossplane · CWE-400 | Düşük2,7 | — | %0,6 | 27 Tem 2023 |
- CVE-2023-3849539İzleyin
Crossplane vulnerable to possible image tampering from missing image validation for Packages
KritikCVSS 9,8İstismar yokEPSS %1cncf · crossplane27 Tem 2023
- CVE-2021-2709832İzleyin
In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SP
YüksekCVSS 8,1İstismar yokEPSS %1cncf · spire5 Mar 2021
- CVE-2019-994631İzleyin
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Ku
YüksekCVSS 7,5İstismar yokEPSS %3cncf · portmap2 Nis 2019
- CVE-2020-865931İzleyin
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e.
YüksekCVSS 7,5İstismar yokEPSS %2cncf · envoy4 Mar 2020
- CVE-2020-866131İzleyin
CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.
YüksekCVSS 7,5İstismar yokEPSS %2cncf · envoy4 Mar 2020
- CVE-2021-2709927İzleyin
In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided throug
OrtaCVSS 6,8İstismar yokEPSS %1cncf · spire5 Mar 2021
- CVE-2020-866421İzleyin
CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context.
OrtaCVSS 5,3İstismar yokEPSS %1cncf · envoy4 Mar 2020
- CVE-2023-3790010İzleyin
Crossplane vulnerable to denial of service from large image
DüşükCVSS 2,7İstismar yokEPSS %1cncf · crossplane27 Tem 2023