Show filters
99 Total Results
Displaying 51-60 of 99
Sort by:
Attacker Value
Unknown
CVE-2021-25735
Disclosure Date: April 14, 2021 (last updated February 23, 2025)
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.
0
Attacker Value
Unknown
CVE-2020-8570
Disclosure Date: January 11, 2021 (last updated February 22, 2025)
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code.
0
Attacker Value
Unknown
CVE-2020-8554
Disclosure Date: December 07, 2020 (last updated February 22, 2025)
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect.
0
Attacker Value
Unknown
CVE-2020-8569
Disclosure Date: November 17, 2020 (last updated February 22, 2025)
Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, is automatically restarted by Kubernetes, and processes the same VolumeSnapshot custom resource after the restart, entering an endless crashloop. Only the volume snapshot feature is affected by this vulnerability. When exploited, users can’t take snapshots of their volumes or delete the snapshots. All other Kubernetes functionality is not affected.
0
Attacker Value
Unknown
CVE-2020-8568
Disclosure Date: November 10, 2020 (last updated February 22, 2025)
Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secrets. This includes paths under var/lib/kubelet/pods that contain other Kubernetes Secrets.
0
Attacker Value
Unknown
CVE-2020-8563
Disclosure Date: October 15, 2020 (last updated February 22, 2025)
In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.
0
Attacker Value
Unknown
CVE-2020-8566
Disclosure Date: October 15, 2020 (last updated February 22, 2025)
In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, < v1.17.13.
0
Attacker Value
Unknown
CVE-2020-8564
Disclosure Date: October 15, 2020 (last updated February 22, 2025)
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13.
0
Attacker Value
Unknown
CVE-2020-8565
Disclosure Date: October 15, 2020 (last updated February 22, 2025)
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.3, <= v1.18.10, <= v1.17.13, < v1.20.0-alpha2.
0
Attacker Value
Unknown
CVE-2020-8553
Disclosure Date: July 29, 2020 (last updated February 21, 2025)
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.
0