CVE-2023-2728
- EPSS 4.35%
- Veröffentlicht 03.07.2023 21:15:09
- Zuletzt bearbeitet 13.02.2025 17:16:22
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specifi...
CVE-2023-2727
- EPSS 0.17%
- Veröffentlicht 03.07.2023 21:15:09
- Zuletzt bearbeitet 13.02.2025 17:16:22
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers...
CVE-2023-2431
- EPSS 0.01%
- Veröffentlicht 16.06.2023 08:15:08
- Zuletzt bearbeitet 12.12.2024 16:15:07
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerabili...
CVE-2021-25749
- EPSS 0.04%
- Veröffentlicht 24.05.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 05:55:20
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.
CVE-2022-3294
- EPSS 0.64%
- Veröffentlicht 01.03.2023 19:15:25
- Zuletzt bearbeitet 21.11.2024 07:19:14
Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kub...
CVE-2022-3162
- EPSS 0.91%
- Veröffentlicht 01.03.2023 19:15:25
- Zuletzt bearbeitet 21.11.2024 07:18:57
Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are t...
CVE-2020-8562
- EPSS 0.06%
- Veröffentlicht 01.02.2022 11:15:10
- Zuletzt bearbeitet 21.11.2024 05:39:02
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers...
- EPSS 0.28%
- Veröffentlicht 07.01.2022 00:15:07
- Zuletzt bearbeitet 22.08.2025 19:16:27
kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This includes but is not limited to the unstructured string fields in objects such as Events.
CVE-2021-25741
- EPSS 33.04%
- Veröffentlicht 20.09.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:19
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
CVE-2021-25740
- EPSS 0.54%
- Veröffentlicht 20.09.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:55:19
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.