VYPR

Spinnaker

by Spinnaker

Source repositories

CVEs (8)

  • CVE-2021-43832CriJan 4, 2022
    risk 0.65cvss 10.0epss 0.03

    Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. This lets an arbitrary user with access to the gate endpoint to create a pipeline and execute it without authentication. If users…

  • CVE-2026-25534CriMar 17, 2026
    risk 0.52cvss 9.1epss 0.00

    ### Impact Spinnaker updated URL Validation logic on user input to provide sanitation on user inputted URLs for clouddriver. However, they missed that Java URL objects do not correctly handle underscores on parsing. This led to a bypass of the previous CVE (CVE-2025-61916)…

  • CVE-2025-61916HigJan 5, 2026
    risk 0.51cvss 7.9epss 0.00

    Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primary impact is allowing users to fetch data from a remote URL. This data can be then injected into…

  • CVE-2026-44795HigJul 10, 2026
    risk 0.50cvss 8.8epss 0.01

    Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows…

  • CVE-2021-39143MedJan 4, 2022
    risk 0.43cvss 6.6epss 0.00

    Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in uses of TAR files by AppEngine for deployments. This uses a utility to extract files locally for deployment without validating the paths in that deployment…

  • CVE-2023-39348MedAug 28, 2023
    risk 0.19cvss 4.0epss 0.00

    Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. It's recommended to apply the patch and rotate the GitHub token used for github status notifications. Given that this would output…

  • CVE-2026-55175HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.01

    Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code…

  • CVE-2022-23506MedJan 3, 2023
    risk 0.00cvss 4.3epss 0.01

    Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces machine images. Rosco prior to versions 1.29.2, 1.28.4, and 1.27.3 does not property mask secrets generated via packer builds. This…