Show filters
131 Total Results
Displaying 11-20 of 131
Sort by:
Attacker Value
Unknown

CVE-2024-5321

Disclosure Date: July 18, 2024 (last updated July 19, 2024)
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may be able to modify container logs.
0
Attacker Value
Unknown

CVE-2024-5042

Disclosure Date: May 17, 2024 (last updated July 17, 2024)
A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.
0
Attacker Value
Unknown

CVE-2024-3727

Disclosure Date: May 14, 2024 (last updated January 20, 2025)
A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
0
Attacker Value
Unknown

CVE-2024-1139

Disclosure Date: April 25, 2024 (last updated May 16, 2024)
A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.
0
Attacker Value
Unknown

CVE-2024-0874

Disclosure Date: April 25, 2024 (last updated September 11, 2024)
A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented caching.
0
Attacker Value
Unknown

CVE-2024-3177

Disclosure Date: April 22, 2024 (last updated September 10, 2024)
A security issue was discovered in Kubernetes where users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using containers, init containers, and ephemeral containers with the envFrom field populated. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the kubernetes.io/enforce-mountable-secrets annotation are used together with containers, init containers, and ephemeral containers with the envFrom field populated.
0
Attacker Value
Unknown

CVE-2024-29990

Disclosure Date: April 09, 2024 (last updated January 12, 2025)
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-23314

Disclosure Date: February 14, 2024 (last updated January 24, 2025)
When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Attacker Value
Unknown

CVE-2024-21403

Disclosure Date: February 13, 2024 (last updated January 12, 2025)
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-21376

Disclosure Date: February 13, 2024 (last updated January 12, 2025)
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability