Vulnerabilidades en kubernetes

103 resultados
Análisis Vexday

Kubernetes apresenta 5 vulnerabilidades catalogadas, das quais 1 é crítica, mas nenhuma está sob ataque ativo no momento. A ausência de publicações recentes (últimos 90 dias) sugere que o risco atual é estável, com a validação inadequada de entrada (CWE-20) como padrão dominante. O perfil de risco é moderado, sem sinais de exploração em massa.

CVE-2020-8565MEDIUMIncomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9EPSS 0.5%CVE-2020-8563MEDIUMSecret leaks in logs for vSphere Provider kube-controller-managerEPSS 0.5%CVE-2026-1580HIGHingress-nginx auth-method nginx configuration injectionEPSS 0.5%CVE-2020-8557MEDIUMKubernetes node disk Denial of Service by writing to container /etc/hostsEPSS 0.5%CVE-2026-24514MEDIUMingress-nginx Admission Controller denial of serviceEPSS 0.5%CVE-2025-15566HIGHingress-nginx auth-proxy-set-headers nginx configuration injectionEPSS 0.5%CVE-2019-11244LOWkubectl creates world-writeable cached schema filesEPSS 0.5%CVE-2021-25738MEDIUMCode exec via yaml parsingEPSS 0.5%CVE-2020-8564MEDIUMDocker config secrets leaked when file is malformed and loglevel >= 4EPSS 0.5%CVE-2025-13281MEDIUMPortworx Half-Blind SSRF in kube-controller-managerEPSS 0.4%CVE-2023-2878MEDIUMKubernetes secrets-store-csi-driver discloses service account tokens in logsEPSS 0.4%CVE-2025-0426MEDIUMA security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet readEPSS 0.4%CVE-2026-15687LOWPath traversal via non-tar copyDirectoryFromPodEPSS 0.4%CVE-2025-7342HIGHVM images built with Kubernetes Image Builder Nutanix or OVA providers use default credentials for Windows images if user did not overrideEPSS 0.3%CVE-2026-24513LOWingress-nginx auth-url protection bypassEPSS 0.3%CVE-2024-7598LOWNetwork restriction bypass via race condition during namespace terminationEPSS 0.3%CVE-2024-5321MEDIUMIncorrect permissions on Windows containers logsEPSS 0.3%CVE-2025-9708MEDIUMKubernetes C# Client: improper certificate validation in custom CA mode may lead to man-in-the-middle attacksEPSS 0.3%CVE-2024-3744MEDIUMKubernetes azure-file-csi-driver in versions before 1.29.4 and 1.30.1 discloses service account tokens in logsEPSS 0.3%CVE-2023-2431LOWBypass of seccomp profile enforcementEPSS 0.3%