VYPR

Karmada

by Karmada Io

Source repositories

CVEs (3)

  • CVE-2024-33396HigMay 2, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue in karmada-io karmada v1.9.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

  • CVE-2024-56513HigJan 3, 2025
    risk 0.50cvss epss 0.00

    Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command have excessive privileges to access…

  • CVE-2024-56514MedJan 3, 2025
    risk 0.28cvss epss 0.01

    Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karmadactl and karmada-operator, it is possible to supply a filesystem path, or an HTTP(s) URL to…