VYPR

Vendor CVEs

Cri O

All CVEs

124 total · sorted by risk
  • CVE-2025-1974CriMar 25, 2025
    risk 0.75cvss 9.8epss 1.00

    A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the…

  • CVE-2025-1098HigMar 25, 2025
    risk 0.67cvss 8.8epss 0.83

    A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of…

  • CVE-2018-1002105CriDec 5, 2018
    risk 0.67cvss 9.8epss 0.87

    In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then…

  • CVE-2023-1174CriMay 24, 2023
    risk 0.64cvss 9.8epss 0.01

    This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container.

  • CVE-2025-24514HigMar 25, 2025
    risk 0.63cvss 8.8epss 0.32

    A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and…

  • CVE-2025-1097HigMar 25, 2025
    risk 0.63cvss 8.8epss 0.35

    A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx…

  • CVE-2024-7646HigAug 16, 2024
    risk 0.59cvss 8.8epss 0.27

    A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx…

  • CVE-2022-0811HigMar 16, 2022
    risk 0.59cvss 8.8epss 0.19

    A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as root on the cluster node, where the…

  • CVE-2026-3288HigMar 9, 2026
    risk 0.58cvss 8.8epss 0.06

    A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of…

  • CVE-2021-25741HigSep 20, 2021
    risk 0.58cvss 8.8epss 0.08

    A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

  • CVE-2019-11248HigAug 29, 2019
    risk 0.58cvss 8.2epss 0.75

    The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and…

  • CVE-2017-1002101HigMar 13, 2018
    risk 0.58cvss 8.8epss 0.12

    In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including…

  • CVE-2025-15566HigFeb 6, 2026
    risk 0.57cvss 8.8epss 0.00

    A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and…

  • CVE-2026-24512HigFeb 3, 2026
    risk 0.57cvss 8.8epss 0.01

    A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the…

  • CVE-2026-1580HigFeb 3, 2026
    risk 0.57cvss 8.8epss 0.00

    A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of…

  • CVE-2022-4886HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.02

    Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.

  • CVE-2017-1000056CriJul 17, 2017
    risk 0.57cvss 9.8epss 0.02

    Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object.

  • CVE-2016-1906CriFeb 3, 2016
    risk 0.57cvss 9.8epss 0.05

    Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.

  • CVE-2023-1944HigMay 24, 2023
    risk 0.55cvss 8.4epss 0.00

    This vulnerability enables ssh access to minikube container using a default password.

  • CVE-2023-5044HigOct 25, 2023
    risk 0.54cvss 7.6epss 0.57

    Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

  • CVE-2024-5154HigJun 12, 2024
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.

  • CVE-2019-11243HigApr 22, 2019
    risk 0.53cvss 8.1epss 0.01

    In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not…

  • CVE-2018-1002103HigDec 5, 2018
    risk 0.53cvss 8.1epss 0.01

    In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM environments where the IP is easy to predict, the attacker can use DNS rebinding to indirectly make requests to the Kubernetes Dashboard, create a new…

  • CVE-2023-1943HigOct 12, 2023
    risk 0.52cvss 8.0epss 0.01

    Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.

  • CVE-2020-8570CriJan 21, 2021
    risk 0.52cvss 9.1epss 0.04

    Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system…

  • CVE-2026-15809HigJul 15, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the…

  • CVE-2023-3676HigOct 31, 2023
    risk 0.51cvss 8.8epss 0.12

    A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.

  • CVE-2021-25749HigMay 24, 2023
    risk 0.51cvss 7.8epss 0.00

    Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.

  • CVE-2026-4342HigMar 19, 2026
    risk 0.50cvss 8.8epss 0.01

    A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the…

  • CVE-2023-3893HigNov 3, 2023
    risk 0.50cvss 8.8epss 0.03

    A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running …

  • CVE-2023-3955HigOct 31, 2023
    risk 0.50cvss 8.8epss 0.03

    A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.

  • CVE-2023-5043HigOct 25, 2023
    risk 0.50cvss 7.6epss 0.02

    Ingress nginx annotation injection causes arbitrary command execution.

  • CVE-2021-25746HigMay 6, 2022
    risk 0.50cvss 7.6epss 0.01

    A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default…

  • CVE-2021-25742HigOct 29, 2021
    risk 0.50cvss 7.6epss 0.02

    A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.

  • CVE-2025-7342HigAug 17, 2025
    risk 0.49cvss 7.5epss 0.00

    A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the Windows image build process when using the Nutanix or VMware OVA providers. These credentials, which allow root access, are disabled at the conclusion of the build.…

  • CVE-2021-25745HigMay 6, 2022
    risk 0.49cvss 7.6epss 0.01

    A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx…

  • CVE-2016-7075HigSep 10, 2018
    risk 0.49cvss 7.5epss 0.02

    It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.

  • CVE-2024-10220HigNov 22, 2024
    risk 0.46cvss 8.1epss 0.03

    The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.

  • CVE-2022-2385HigJul 12, 2022
    risk 0.46cvss 8.1epss 0.01

    A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.

  • CVE-2019-11247HigAug 29, 2019
    risk 0.46cvss 8.1epss 0.02

    The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced. Authorizations for the resource accessed in this manner are enforced using roles and role bindings within the namespace, meaning…

  • CVE-2017-1002102HigMar 13, 2018
    risk 0.46cvss 7.1epss 0.01

    In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.

  • CVE-2023-1260HigSep 24, 2023
    risk 0.45cvss 8.0epss 0.02

    An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a…

  • CVE-2022-4318HigSep 25, 2023
    risk 0.44cvss 7.8epss 0.00

    A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

  • CVE-2021-25738MedOct 11, 2021
    risk 0.44cvss 6.7epss 0.00

    Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.

  • CVE-2025-0750MedJan 28, 2025
    risk 0.43cvss 6.6epss 0.00

    A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by…

  • CVE-2024-0793HigNov 17, 2024
    risk 0.43cvss 7.7epss 0.01

    A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.

  • CVE-2022-3294MedMar 1, 2023
    risk 0.43cvss 6.6epss 0.02

    Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access…

  • CVE-2019-11249MedAug 29, 2019
    risk 0.43cvss 6.5epss 0.04

    The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in…

  • CVE-2019-1002100MedApr 1, 2019
    risk 0.43cvss 6.5epss 0.10

    In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type:…

  • CVE-2016-1905HigFeb 3, 2016
    risk 0.43cvss 7.7epss 0.02

    The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.

Page 1 of 3