Show filters
131 Total Results
Displaying 121-130 of 131
Sort by:
Attacker Value
Unknown
CVE-2018-1999040
Disclosure Date: August 01, 2018 (last updated November 27, 2024)
An exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.10.1 and earlier in KubernetesCloud.java that allows attackers to capture credentials with a known credentials ID stored in Jenkins.
0
Attacker Value
Unknown
CVE-2018-1000187
Disclosure Date: June 05, 2018 (last updated November 26, 2024)
A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive variables such as passwords being written to logs.
0
Attacker Value
Unknown
CVE-2018-1002100
Disclosure Date: June 02, 2018 (last updated November 26, 2024)
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.
0
Attacker Value
Unknown
CVE-2017-1002102
Disclosure Date: March 13, 2018 (last updated November 26, 2024)
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.
0
Attacker Value
Unknown
CVE-2017-1002101
Disclosure Date: March 13, 2018 (last updated November 26, 2024)
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
0
Attacker Value
Unknown
CVE-2017-1002100
Disclosure Date: September 14, 2017 (last updated November 26, 2024)
Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to the URI string requires privileged access to the Kubernetes cluster or authenticated access to the Azure portal.
0
Attacker Value
Unknown
CVE-2015-7561
Disclosure Date: August 07, 2017 (last updated November 26, 2024)
Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.
0
Attacker Value
Unknown
CVE-2017-1000056
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object.
0
Attacker Value
Unknown
CVE-2015-7528
Disclosure Date: April 11, 2016 (last updated November 25, 2024)
Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name.
0
Attacker Value
Unknown
CVE-2016-1905
Disclosure Date: February 03, 2016 (last updated November 25, 2024)
The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.
0