Kubeflow
by Kubeflow
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-5552 | Hig | 0.49 | 7.5 | 0.01 | Jun 6, 2024 | kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expression complexity in its email validation mechanism. An attacker can remotely exploit this vulnerability without authentication by providing specially crafted… | ||
| CVE-2023-6570 | Med | 0.42 | 6.5 | 0.01 | Dec 14, 2023 | Server-Side Request Forgery (SSRF) in kubeflow/kubeflow | ||
| CVE-2023-6571 | Med | 0.40 | 6.1 | 0.00 | Dec 14, 2023 | Cross-site Scripting (XSS) - Reflected in kubeflow/kubeflow |
- risk 0.49cvss 7.5epss 0.01
kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expression complexity in its email validation mechanism. An attacker can remotely exploit this vulnerability without authentication by providing specially crafted…
- risk 0.42cvss 6.5epss 0.01
Server-Side Request Forgery (SSRF) in kubeflow/kubeflow
- risk 0.40cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Reflected in kubeflow/kubeflow