VYPR
Vendor

Clastix

Products
3
CVEs
7
Across products
9
Status
Private

Products

3

Recent CVEs

7
  • CVE-2023-48312CriNov 24, 2023
    risk 0.57cvss 9.8epss 0.01

    capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalation vulnerability which is based on a missing check if the user is authenticated based on the `TokenReview` result. All the clusters running with the…

  • CVE-2022-46167HigDec 2, 2022
    risk 0.50cvss 8.8epss 0.01

    Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to version 0.1.3, a ServiceAccount deployed in a Tenant Namespace, when granted with `PATCH` capabilities on its own Namespace, is able to edit it and remove the Owner Reference, breaking the…

  • CVE-2022-23652HigFeb 22, 2022
    risk 0.50cvss 8.8epss 0.01

    capsule-proxy is a reverse proxy for Capsule Operator which provides multi-tenancy in Kubernetes. In versions prior to 0.2.1 an attacker with a proper authentication mechanism may use a malicious `Connection` header to start a privilege escalation attack towards the Kubernetes…

  • CVE-2026-62246HigJul 30, 2026
    risk 0.48cvss 8.5epss 0.00

    Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and…

  • CVE-2024-42480HigAug 12, 2024
    risk 0.46cvss 8.1epss 0.01

    Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other control planes. This…

  • CVE-2026-62845MedJul 30, 2026
    risk 0.24cvss 4.7epss 0.00

    Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers.…

  • CVE-2023-46254MedNov 6, 2023
    risk 0.21cvss 4.3epss 0.00

    capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used by `capsule-proxy` gives ServiceAccount tenant owners the right to list Namespaces of other tenants backed by the same owner kind and name. For example…