kubernetes kayıtları
kubernetes üreticisine ait 102 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %90,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation26
- CWE-532 Insertion of Sensitive Information into Log File6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-61 UNIX Symbolic Link (Symlink) Following3
- CWE-284 Improper Access Control3
- CWE-266 Incorrect Privilege Assignment2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
102 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
65Bu hafta | CVE-2018-1002105Kavram kanıtı | In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in thekubernetes · kubernetes · CWE-388 | Kritik9,8 | — | %87,0 | 5 Ara 2018 |
55Planlayın | CVE-2019-11248Kavram kanıtı | Kubernetes kubelet exposes /debug/pprof info on healthz portkubernetes · kubernetes · CWE-419 | Yüksek8,2 | — | %75,1 | 28 Ağu 2019 |
52Planlayın | CVE-2023-5044Kavram kanıtı | Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotationkubernetes · ingress-nginx · CWE-20 | Yüksek8,8 | — | %56,6 | 25 Eki 2023 |
51Planlayın | CVE-2018-18264Kavram kanıtı | Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within kubernetes · dashboard · CWE-306 | Yüksek7,5 | — | %70,4 | 2 Oca 2019 |
43Planlayın | CVE-2024-7646Kavram kanıtı | A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `exkubernetes · ingress-nginx · CWE-20 | Yüksek8,8 | — | %27,0 | 16 Ağu 2024 |
42Planlayın | CVE-2017-1002101Kavram kanıtı | In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with kubernetes · kubernetes · CWE-59 | Kritik9,6 | — | %12,9 | 13 Mar 2018 |
41Planlayın | CVE-2022-0811Kavram kanıtı | A flaw was found in CRI-O in the way it set kernel options for a pod.kubernetes · cri-o · CWE-94 | Yüksek8,8 | — | %19,0 | 16 Mar 2022 |
40Planlayın | CVE-2016-1906İstismar yok | Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that kubernetes · kubernetes · CWE-264 | Kritik9,8 | — | %4,8 | 3 Şub 2016 |
40Planlayın | CVE-2018-1002101İstismar yok | In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Wikubernetes · kubernetes | Kritik9,8 | — | %4,0 | 5 Ara 2018 |
40Planlayın | CVE-2017-1000056İstismar yok | Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability tokubernetes · kubernetes · CWE-862 | Kritik9,8 | — | %2,8 | 17 Tem 2017 |
40Planlayın | CVE-2025-57870İstismar yok | BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services.esri · arcgis server · CWE-89 | Kritik10,0 | — | %0,5 | 22 Eki 2025 |
39İzleyin | CVE-2023-3676İstismar yok | Kubernetes - Windows nodes - Insufficient input sanitization leads to privilege escalationkubernetes · kubernetes · CWE-20 | Yüksek8,8 | — | %13,2 | 31 Eki 2023 |
39İzleyin | CVE-2026-13019İstismar yok | Missing Authenticationesri · portal for arcgis · CWE-640 | Kritik9,8 | — | %0,8 | 7 Tem 2026 |
39İzleyin | CVE-2023-1174İstismar yok | [minikube] Network Port exposure in minikube running on macOS using Docker driverkubernetes · minikube · CWE-266 | Kritik9,8 | — | %0,8 | 24 May 2023 |
39İzleyin | CVE-2026-33519İstismar yok | Incorrect privilege assignment in Portal for ArcGISesri · portal for arcgis · CWE-266 | Kritik9,8 | — | %0,5 | 21 Nis 2026 |
39İzleyin | CVE-2026-13020İstismar yok | Weak Password Recovery Mechanism in Portal for ArcGISesri · portal for arcgis · CWE-640 | Kritik9,8 | — | %0,5 | 7 Tem 2026 |
38İzleyin | CVE-2019-11253Kavram kanıtı | Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attackkubernetes · kubernetes · CWE-20 | Yüksek7,5 | — | %25,9 | 17 Eki 2019 |
37İzleyin | CVE-2020-8570Kavram kanıtı | Kubernetes Java client libraries unvalidated path traversal in Copy implementationkubernetes · java · CWE-23 | Kritik9,1 | — | %3,6 | 21 Oca 2021 |
36İzleyin | CVE-2023-5528İstismar yok | Kubernetes - Windows nodes - Insufficient input sanitization in in-tree storage plugin leads to privilege escalationkubernetes · kubernetes · CWE-20 | Yüksek8,8 | — | %4,3 | 14 Kas 2023 |
36İzleyin | CVE-2023-3955İstismar yok | Kubernetes - Windows nodes - Insufficient input sanitization leads to privilege escalationkubernetes · kubernetes · CWE-20 | Yüksek8,8 | — | %4,0 | 31 Eki 2023 |
36İzleyin | CVE-2020-8558Kavram kanıtı | Kubernetes node setting allows for neighboring hosts to bypass localhost boundarykubernetes · kubernetes · CWE-420 | Yüksek8,8 | — | %3,6 | 27 Tem 2020 |
36İzleyin | CVE-2023-3893İstismar yok | Kubernetes - csi-proxy - Insufficient input sanitization leads to privilege escalationkubernetes · csi proxy · CWE-20 | Yüksek8,8 | — | %2,5 | 3 Kas 2023 |
36İzleyin | CVE-2023-5043Kavram kanıtı | Ingress nginx annotation injection causes arbitrary command executionkubernetes · ingress-nginx · CWE-20 | Yüksek8,8 | — | %2,2 | 25 Eki 2023 |
36İzleyin | CVE-2018-1000400İstismar yok | Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabikubernetes · cri-o · CWE-269 | Yüksek8,8 | — | %2,0 | 18 May 2018 |
35İzleyin | CVE-2022-3294Kavram kanıtı | Node address isn't always verified when proxyingkubernetes · kubernetes · CWE-20 | Yüksek8,8 | — | %1,6 | 1 Mar 2023 |
- CVE-2018-100210565Bu hafta
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the
KritikCVSS 9,8Kavram kanıtıEPSS %87kubernetes · kubernetes5 Ara 2018
- CVE-2019-1124855Planlayın
Kubernetes kubelet exposes /debug/pprof info on healthz port
YüksekCVSS 8,2Kavram kanıtıEPSS %75kubernetes · kubernetes28 Ağu 2019
- CVE-2023-504452Planlayın
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
YüksekCVSS 8,8Kavram kanıtıEPSS %57kubernetes · ingress-nginx25 Eki 2023
- CVE-2018-1826451Planlayın
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within
YüksekCVSS 7,5Kavram kanıtıEPSS %70kubernetes · dashboard2 Oca 2019
- CVE-2024-764643Planlayın
A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `ex
YüksekCVSS 8,8Kavram kanıtıEPSS %27kubernetes · ingress-nginx16 Ağu 2024
- CVE-2017-100210142Planlayın
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with
KritikCVSS 9,6Kavram kanıtıEPSS %13kubernetes · kubernetes13 Mar 2018
- CVE-2022-081141Planlayın
A flaw was found in CRI-O in the way it set kernel options for a pod.
YüksekCVSS 8,8Kavram kanıtıEPSS %19kubernetes · cri-o16 Mar 2022
- CVE-2016-190640Planlayın
Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that
KritikCVSS 9,8İstismar yokEPSS %5kubernetes · kubernetes3 Şub 2016
- CVE-2018-100210140Planlayın
In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Wi
KritikCVSS 9,8İstismar yokEPSS %4kubernetes · kubernetes5 Ara 2018
- CVE-2017-100005640Planlayın
Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to
KritikCVSS 9,8İstismar yokEPSS %3kubernetes · kubernetes17 Tem 2017
- CVE-2025-5787040Planlayın
BUG-000179884 - There is a security vulnerability in ArcGIS Server Feature Services.
KritikCVSS 10,0İstismar yokEPSS %1esri · arcgis server22 Eki 2025
- CVE-2023-367639İzleyin
Kubernetes - Windows nodes - Insufficient input sanitization leads to privilege escalation
YüksekCVSS 8,8İstismar yokEPSS %13kubernetes · kubernetes31 Eki 2023
- CVE-2026-1301939İzleyin
Missing Authentication
KritikCVSS 9,8İstismar yokEPSS %1esri · portal for arcgis7 Tem 2026
- CVE-2023-117439İzleyin
[minikube] Network Port exposure in minikube running on macOS using Docker driver
KritikCVSS 9,8İstismar yokEPSS %1kubernetes · minikube24 May 2023
- CVE-2026-3351939İzleyin
Incorrect privilege assignment in Portal for ArcGIS
KritikCVSS 9,8İstismar yokEPSS %0esri · portal for arcgis21 Nis 2026
- CVE-2026-1302039İzleyin
Weak Password Recovery Mechanism in Portal for ArcGIS
KritikCVSS 9,8İstismar yokEPSS %0esri · portal for arcgis7 Tem 2026
- CVE-2019-1125338İzleyin
Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
YüksekCVSS 7,5Kavram kanıtıEPSS %26kubernetes · kubernetes17 Eki 2019
- CVE-2020-857037İzleyin
Kubernetes Java client libraries unvalidated path traversal in Copy implementation
KritikCVSS 9,1Kavram kanıtıEPSS %4kubernetes · java21 Oca 2021
- CVE-2023-552836İzleyin
Kubernetes - Windows nodes - Insufficient input sanitization in in-tree storage plugin leads to privilege escalation
YüksekCVSS 8,8İstismar yokEPSS %4kubernetes · kubernetes14 Kas 2023
- CVE-2023-395536İzleyin
Kubernetes - Windows nodes - Insufficient input sanitization leads to privilege escalation
YüksekCVSS 8,8İstismar yokEPSS %4kubernetes · kubernetes31 Eki 2023
- CVE-2020-855836İzleyin
Kubernetes node setting allows for neighboring hosts to bypass localhost boundary
YüksekCVSS 8,8Kavram kanıtıEPSS %4kubernetes · kubernetes27 Tem 2020
- CVE-2023-389336İzleyin
Kubernetes - csi-proxy - Insufficient input sanitization leads to privilege escalation
YüksekCVSS 8,8İstismar yokEPSS %2kubernetes · csi proxy3 Kas 2023
- CVE-2023-504336İzleyin
Ingress nginx annotation injection causes arbitrary command execution
YüksekCVSS 8,8Kavram kanıtıEPSS %2kubernetes · ingress-nginx25 Eki 2023
- CVE-2018-100040036İzleyin
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabi
YüksekCVSS 8,8İstismar yokEPSS %2kubernetes · cri-o18 May 2018
- CVE-2022-329435İzleyin
Node address isn't always verified when proxying
YüksekCVSS 8,8Kavram kanıtıEPSS %2kubernetes · kubernetes1 Mar 2023