VYPR

Kubernetes

by Cri O

Source repositories

CVEs (75)

  • CVE-2024-5321MedJul 18, 2024
    risk 0.33cvss 6.1epss 0.00

    A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.

  • CVE-2018-1002101MedDec 5, 2018
    risk 0.32cvss 5.9epss 0.04

    In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Windows nodes, which could lead to command line argument injection.

  • CVE-2025-13281MedDec 14, 2025
    risk 0.31cvss 5.8epss 0.00

    A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network…

  • CVE-2024-9042MedMar 13, 2025
    risk 0.31cvss 5.9epss 0.01

    This CVE affects only Windows worker nodes. Your worker node is vulnerable to this issue if it is running one of the affected versions listed below.

  • CVE-2021-25736MedOct 30, 2023
    risk 0.31cvss 5.8epss 0.01

    Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” field. Clusters where the…

  • CVE-2020-8557MedJul 23, 2020
    risk 0.29cvss 5.5epss 0.01

    The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file. The /etc/hosts file mounted in a pod by kubelet is not included by the kubelet eviction manager when…

  • CVE-2020-8552MedMar 27, 2020
    risk 0.28cvss 5.3epss 0.02

    The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.

  • CVE-2015-7528MedApr 11, 2016
    risk 0.28cvss 5.3epss 0.02

    Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name.

  • CVE-2020-8561MedSep 20, 2021
    risk 0.27cvss 4.1epss 0.02

    A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view…

  • CVE-2018-1002100MedJun 2, 2018
    risk 0.27cvss 4.2epss 0.02

    In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.

  • CVE-2019-11244MedApr 22, 2019
    risk 0.26cvss 5.0epss 0.00

    In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to…

  • CVE-2020-8565MedDec 7, 2020
    risk 0.24cvss 4.7epss 0.01

    In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.

  • CVE-2020-8564MedDec 7, 2020
    risk 0.24cvss 4.7epss 0.00

    In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.

  • CVE-2020-8551MedMar 27, 2020
    risk 0.21cvss 4.3epss 0.01

    The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API…

  • CVE-2026-24513LowFeb 3, 2026
    risk 0.20cvss 3.1epss 0.00

    A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific misconfiguration. If the ingress-nginx controller is configured with a default custom-errors configuration…

  • CVE-2024-7598LowMar 20, 2025
    risk 0.20cvss 3.1epss 0.00

    A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The order in which objects are deleted during namespace termination is not defined, and it is possible for…

  • CVE-2021-25740LowSep 20, 2021
    risk 0.20cvss 3.1epss 0.02

    A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

  • CVE-2021-25737LowSep 6, 2021
    risk 0.18cvss 2.7epss 0.01

    A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.

  • CVE-2018-1002102LowDec 5, 2019
    risk 0.17cvss 2.6epss 0.01

    Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with…

  • CVE-2023-2431LowJun 16, 2023
    risk 0.15cvss 3.4epss 0.00

    A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in…