VYPR

apk package

chainguard/aws-efs-csi-driver-fips

pkg:apk/chainguard/aws-efs-csi-driver-fips

Vulnerabilities (85)

  • CVE-2023-3676HigOct 31, 2023
    affected < 1.7.0-r5fixed 1.7.0-r5

    A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.

  • CVE-2023-39325HigOct 11, 2023
    affected < 1.7.0-r3fixed 1.7.0-r3

    A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attack

  • CVE-2023-44487HigKEVOct 10, 2023
    affected < 3.1.0-r0fixed 3.1.0-r0

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2021-25743LowJan 7, 2022
    affected < 2.1.14-r1fixed 2.1.14-r1

    kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

  • CVE-2020-8559MedJul 22, 2020
    affected < 2.1.7-r0fixed 2.1.7-r0

    The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

Page 5 of 5