Vulnerabilidades em projectcapsule
12 resultadosAnálise Vexday
O Project Capsule apresenta um perfil de risco moderado com 6 vulnerabilidades catalogadas, das quais 2 são críticas; nenhuma está sob exploração ativa conhecida no momento. A fraqueza dominante (CWE-863 - autorização inadequada) indica problemas de controle de acesso, com 2 CVEs publicadas nos últimos 90 dias sugerindo atividade recente de descoberta de vulnerabilidades neste componente.
CVE-2026-22872MEDIUMCapsule TenantResource RawItems Cluster-Scoped Resource Creation VulnerabilityEPSS 0.7%CVE-2026-61794MEDIUMCapsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panicEPSS 0.6%CVE-2026-61795MEDIUMCapsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validationEPSS 0.6%CVE-2023-48312CRITICALAuthentication bypass using an empty token in capsule-proxyEPSS 0.6%CVE-2024-39690HIGHCapsule tenant owner with "patch namespace" permission can hijack system namespacesEPSS 0.5%CVE-2026-65834MEDIUMCapsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requestsEPSS 0.5%CVE-2025-55205CRITICALCapsule tenant owners with "patch namespace" permission can hijack system namespaces labelEPSS 0.5%CVE-2023-46254MEDIUMService accounts can see namespaces of other tenants in capsule-proxyEPSS 0.4%CVE-2026-55636MEDIUMCapsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotectedEPSS 0.4%CVE-2026-61672HIGHCapsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcementEPSS 0.3%CVE-2026-65835MEDIUMCapsule: Incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)EPSS 0.3%CVE-2026-30963LOWCapsule Namespace Hijacking via subresourceEPSS 0.3%