weave kayıtları
weave üreticisine ait 10 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-284 Improper Access Control1
- CWE-306 Missing Authentication for Critical Function1
- CWE-350 Reliance on Reverse DNS Resolution for a Security-Critical Action1
- CWE-358 Improperly Implemented Security Check for Standard1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
10 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-35464İstismar yok | Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user.weave · cloud agent · CWE-306 | Kritik9,8 | — | %2,1 | 15 Ara 2020 |
39İzleyin | CVE-2022-35975İstismar yok | Improper object validation allows for arbitrary code execution in GitOps Tools Extension for VSCodeweave · gitops tools · CWE-78 | Kritik9,8 | — | %1,3 | 18 Ağu 2022 |
39İzleyin | CVE-2022-35976İstismar yok | Improper KubeConfig handling allows arbitrary code executionweave · gitops tools · CWE-78 | Kritik9,8 | — | %0,5 | 18 Ağu 2022 |
32İzleyin | CVE-2020-26278İstismar yok | Weave Net Pods running in host PID namespace can be used to escalate other Kubernetes vulnerabilitiesweave · weave · CWE-250 | Yüksek8,0 | — | %0,7 | 20 Oca 2021 |
31İzleyin | CVE-2022-23508İstismar yok | GitOps Run allows for Kubernetes workload injectionweave · weave gitops · CWE-284 | Yüksek7,8 | — | %0,3 | 9 Oca 2023 |
31İzleyin | CVE-2024-25545İstismar yok | An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework compoweave · weave desktop · CWE-358 | Yüksek7,8 | — | %0,2 | 12 Nis 2024 |
30İzleyin | CVE-2022-31098İstismar yok | Weave GitOps leaked cluster credentials into logs on connection errorsweave · weave gitops · CWE-532 | Yüksek7,5 | — | %1,2 | 27 Haz 2022 |
26İzleyin | CVE-2023-34236İstismar yok | Information Disclosure Vulnerability in Weave GitOps Terraform Controllerweave · gitops terraform controller · CWE-200 | Orta6,5 | — | %1,0 | 14 Tem 2023 |
24İzleyin | CVE-2022-23509İstismar yok | Weave Gitops Run vulnerable to insecure communicationweave · weave gitops · CWE-200 | Orta6,0 | — | %0,2 | 9 Oca 2023 |
23İzleyin | CVE-2020-11091İstismar yok | Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisementsweave · weave net · CWE-350 | Orta5,8 | — | %0,9 | 3 Haz 2020 |
- CVE-2020-3546440Planlayın
Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user.
KritikCVSS 9,8İstismar yokEPSS %2weave · cloud agent15 Ara 2020
- CVE-2022-3597539İzleyin
Improper object validation allows for arbitrary code execution in GitOps Tools Extension for VSCode
KritikCVSS 9,8İstismar yokEPSS %1weave · gitops tools18 Ağu 2022
- CVE-2022-3597639İzleyin
Improper KubeConfig handling allows arbitrary code execution
KritikCVSS 9,8İstismar yokEPSS %1weave · gitops tools18 Ağu 2022
- CVE-2020-2627832İzleyin
Weave Net Pods running in host PID namespace can be used to escalate other Kubernetes vulnerabilities
YüksekCVSS 8,0İstismar yokEPSS %1weave · weave20 Oca 2021
- CVE-2022-2350831İzleyin
GitOps Run allows for Kubernetes workload injection
YüksekCVSS 7,8İstismar yokEPSS %0weave · weave gitops9 Oca 2023
- CVE-2024-2554531İzleyin
An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework compo
YüksekCVSS 7,8İstismar yokEPSS %0weave · weave desktop12 Nis 2024
- CVE-2022-3109830İzleyin
Weave GitOps leaked cluster credentials into logs on connection errors
YüksekCVSS 7,5İstismar yokEPSS %1weave · weave gitops27 Haz 2022
- CVE-2023-3423626İzleyin
Information Disclosure Vulnerability in Weave GitOps Terraform Controller
OrtaCVSS 6,5İstismar yokEPSS %1weave · gitops terraform controller14 Tem 2023
- CVE-2022-2350924İzleyin
Weave Gitops Run vulnerable to insecure communication
OrtaCVSS 6,0İstismar yokEPSS %0weave · weave gitops9 Oca 2023
- CVE-2020-1109123İzleyin
Weave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisements
OrtaCVSS 5,8İstismar yokEPSS %1weave · weave net3 Haz 2020