VYPR

apk package

wolfi/kubeflow-pipelines-apiserver

pkg:apk/wolfi/kubeflow-pipelines-apiserver

Vulnerabilities (127)

  • CVE-2019-11253Oct 17, 2019
    affected < 0fixed 0

    Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crash

  • CVE-2019-11250Aug 29, 2019
    affected < 0fixed 0

    The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authe

  • CVE-2019-1002101Apr 1, 2019
    affected < 0fixed 0

    The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in the container is mali

  • CVE-2019-1002100Apr 1, 2019
    affected < 0fixed 0

    In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+jso

  • CVE-2018-1002105Dec 5, 2018
    affected < 0fixed 0

    In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send

  • CVE-2018-1002101Dec 5, 2018
    affected < 0fixed 0

    In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Windows nodes, which could lead to command line argument injection.

  • CVE-2017-16137Jun 7, 2018
    affected < 2.4.0-r7fixed 2.4.0-r7

    The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.

Page 7 of 7