VYPR
Vendor

Weaveworks

Products
5
CVEs
7
Across products
7
Status
Private

Products

5

Recent CVEs

7
  • CVE-2022-23509Jan 9, 2023
    risk 0.00cvss epss 0.00

    Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. GitOps run has a local S3 bucket which it uses for synchronizing files that are later applied against a Kubernetes cluster. The…

  • CVE-2022-23508Jan 9, 2023
    risk 0.00cvss epss 0.00

    Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a Kubernetes cluster's resources. GitOps run has a local S3…

  • CVE-2022-38790Sep 1, 2022
    risk 0.00cvss epss 0.00

    Weave GitOps Enterprise before 0.9.0-rc.5 has a cross-site scripting (XSS) bug allowing a malicious user to inject a javascript: link in the UI. When clicked by a victim user, the script will execute with the victim's permission. The exposure appears in Weave GitOps Enterprise…

  • CVE-2022-35975Aug 18, 2022
    risk 0.00cvss epss 0.01

    The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution in the machine running the extension, in the context of the user that is running VSCode. Users using the VSCode extension to…

  • CVE-2022-31098Jun 27, 2022
    risk 0.00cvss epss 0.00

    Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to view sensitive cluster configurations, aka…

  • CVE-2020-26278Jan 20, 2021
    risk 0.00cvss epss 0.00

    Weave Net is open source software which creates a virtual network that connects Docker containers across multiple hosts and enables their automatic discovery. Weave Net before version 2.8.0 has a vulnerability in which can allow an attacker to take over any host in the cluster.…

  • CVE-2020-11091Jun 3, 2020
    risk 0.00cvss epss 0.00

    In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fake service. In a cluster with an IPv4 internal network, if IPv6 is not totally disabled on the host…