VYPR
Vendor

Weave

Products
10
CVEs
12
Across products
12
Status
Private

Products

10

Recent CVEs

12
  • CVE-2020-35464CriDec 15, 2020
    risk 0.64cvss 9.8epss 0.02

    Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may allow a remote attacker to achieve root access with a blank password.

  • CVE-2022-35975CriAug 18, 2022
    risk 0.59cvss 9.0epss 0.01

    The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution in the machine running the extension, in the context of the user that is running VSCode. Users using the VSCode extension to…

  • CVE-2019-5038HigAug 20, 2019
    risk 0.57cvss 8.8epss 0.03

    An exploitable command execution vulnerability exists in the print-tlv command of Weave tool. A specially crafted weave TLV can trigger a stack-based buffer overflow, resulting in code execution. An attacker can trigger this vulnerability by convincing the user to open a…

  • CVE-2022-31098CriJun 27, 2022
    risk 0.52cvss 9.0epss 0.01

    Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to view sensitive cluster configurations, aka…

  • CVE-2024-25545HigApr 12, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework component.

  • CVE-2023-34236HigJul 14, 2023
    risk 0.48cvss 8.5epss 0.01

    Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in a GitOps way. A vulnerability has been identified in Weave GitOps Terraform Controller which could allow an authenticated remote attacker to view sensitive…

  • CVE-2022-38790MedSep 1, 2022
    risk 0.35cvss 5.4epss 0.01

    Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permission. The exposure appears in Weave GitOps Enterprise…

  • CVE-2022-35976MedAug 18, 2022
    risk 0.34cvss 5.2epss 0.00

    The GitOps Tools Extension for VSCode relies on kubeconfigs in order to communicate with Kubernetes clusters. A specially crafted kubeconfig leads to arbitrary code execution on behalf of the user running VSCode. Users relying on kubeconfigs that are generated or altered by…

  • CVE-2020-11091MedJun 3, 2020
    risk 0.31cvss 5.8epss 0.01

    In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fake service. In a cluster with an IPv4 internal network, if IPv6 is not totally disabled on the host…

  • CVE-2022-23509HigJan 9, 2023
    risk 0.00cvss 7.3epss 0.00

    Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. GitOps run has a local S3 bucket which it uses for synchronizing files that are later applied against a Kubernetes cluster. The…

  • CVE-2022-23508HigJan 9, 2023
    risk 0.00cvss 8.8epss 0.00

    Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a Kubernetes cluster's resources. GitOps run has a local S3…

  • CVE-2020-26278MedJan 20, 2021
    risk 0.00cvss 5.8epss 0.01

    Weave Net is open source software which creates a virtual network that connects Docker containers across multiple hosts and enables their automatic discovery. Weave Net before version 2.8.0 has a vulnerability in which can allow an attacker to take over any host in the cluster.…