Show filters
131 Total Results
Displaying 51-60 of 131
Sort by:
Attacker Value
Unknown

CVE-2022-27191

Disclosure Date: March 18, 2022 (last updated November 08, 2023)
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
Attacker Value
Unknown

CVE-2022-27211

Disclosure Date: March 15, 2022 (last updated October 10, 2023)
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2022-27210

Disclosure Date: March 15, 2022 (last updated October 25, 2023)
A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2022-27209

Disclosure Date: March 15, 2022 (last updated December 23, 2023)
A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2022-27208

Disclosure Date: March 15, 2022 (last updated October 25, 2023)
Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read arbitrary files on the Jenkins controller.
Attacker Value
Unknown

CVE-2022-23773

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.
Attacker Value
Unknown

CVE-2022-23772

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
Attacker Value
Unknown

CVE-2021-25741

Disclosure Date: September 20, 2021 (last updated February 23, 2025)
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
Attacker Value
Unknown

CVE-2020-8561

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs.
Attacker Value
Unknown

CVE-2021-25740

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.