VYPR

Kubeflow

by Kubeflow

CVEs (3)

  • CVE-2024-5552HigJun 6, 2024
    risk 0.49cvss 7.5epss 0.01

    kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expression complexity in its email validation mechanism. An attacker can remotely exploit this vulnerability without authentication by providing specially crafted…

  • CVE-2023-6570MedDec 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Server-Side Request Forgery (SSRF) in kubeflow/kubeflow

  • CVE-2023-6571MedDec 14, 2023
    risk 0.40cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Reflected in kubeflow/kubeflow