VYPR

Vendor CVEs

Cri O

All CVEs

124 total · sorted by risk
  • CVE-2021-25740LowSep 20, 2021
    risk 0.20cvss 3.1epss 0.02

    A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

  • CVE-2021-25737LowSep 6, 2021
    risk 0.18cvss 2.7epss 0.01

    A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.

  • CVE-2018-1002102LowDec 5, 2019
    risk 0.17cvss 2.6epss 0.01

    Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with…

  • CVE-2023-2431LowJun 16, 2023
    risk 0.15cvss 3.4epss 0.00

    A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in…

  • CVE-2020-8562LowFeb 1, 2022
    risk 0.14cvss 2.2epss 0.01

    As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation…

  • CVE-2021-25743LowJan 7, 2022
    risk 0.13cvss 3.0epss 0.01

    kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.

  • CVE-2015-7561LowAug 7, 2017
    risk 0.13cvss 3.1epss 0.01

    Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.

  • CVE-2025-4563LowJun 23, 2025
    risk 0.11cvss 2.7epss 0.01

    A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled, the controller properly validates resource claim statuses during pod status…

  • CVE-2024-3177LowApr 22, 2024
    risk 0.11cvss 2.7epss 0.02

    A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated.…

  • CVE-2018-18264HigJan 3, 2019
    risk 0.06cvss 7.5epss 0.70

    Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.

  • CVE-2019-11253HigOct 17, 2019
    risk 0.02cvss 7.5epss 0.26

    Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially…

  • CVE-2024-9676MedOct 15, 2024
    risk 0.00cvss 6.5epss 0.01

    A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned…

  • CVE-2021-25748HigMay 24, 2023
    risk 0.00cvss 7.6epss 0.01

    A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API…

  • CVE-2022-0532MedFeb 9, 2022
    risk 0.00cvss 4.2epss 0.01

    An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.

  • CVE-2020-8566MedDec 7, 2020
    risk 0.00cvss 4.7epss 0.01

    In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, <…

  • CVE-2020-8563MedDec 7, 2020
    risk 0.00cvss 4.7epss 0.01

    In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.

  • CVE-2019-11252MedJul 23, 2020
    risk 0.00cvss 5.9epss 0.01

    The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages in mount failure logs and events for AzureFile and CephFS volumes.

  • CVE-2020-8559MedJul 22, 2020
    risk 0.00cvss 6.4epss 0.06

    The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.

  • CVE-2020-8555MedJun 5, 2020
    risk 0.00cvss 6.3epss 0.04

    The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from…

  • CVE-2019-11251MedFeb 3, 2020
    risk 0.00cvss 4.8epss 0.03

    The Kubernetes kubectl cp command in versions 1.1-1.12, and versions prior to 1.13.11, 1.14.7, and 1.15.4 allows a combination of two symlinks provided by tar output of a malicious container to place a file outside of the destination directory specified in the kubectl cp…

  • CVE-2019-11246MedAug 29, 2019
    risk 0.00cvss 6.5epss 0.04

    The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in…

  • CVE-2019-11245MedAug 29, 2019
    risk 0.00cvss 4.9epss 0.01

    In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (root) on container restart, or if the image was previously pulled to the node. If the pod specified mustRunAsNonRoot: true, the kubelet will refuse to start the…

  • CVE-2019-9946HigApr 2, 2019
    risk 0.00cvss 7.5epss 0.03

    Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take…

  • CVE-2018-1000400HigMay 18, 2018
    risk 0.00cvss 8.8epss 0.02

    Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not have. This attack appears…

Page 3 of 3