Show filters
99 Total Results
Displaying 91-99 of 99
Sort by:
Attacker Value
Unknown

CVE-2018-1000400

Disclosure Date: May 18, 2018 (last updated November 26, 2024)
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not have. This attack appears to be exploitable via container execution. This vulnerability appears to have been fixed in 1.9.
0
Attacker Value
Unknown

CVE-2017-1002102

Disclosure Date: March 13, 2018 (last updated November 26, 2024)
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running.
0
Attacker Value
Unknown

CVE-2017-1002101

Disclosure Date: March 13, 2018 (last updated November 26, 2024)
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
0
Attacker Value
Unknown

CVE-2017-1002100

Disclosure Date: September 14, 2017 (last updated November 26, 2024)
Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0 to 1.6.5 are set to "container" which exposes a URI that can be accessed without authentication on the public internet. Access to the URI string requires privileged access to the Kubernetes cluster or authenticated access to the Azure portal.
0
Attacker Value
Unknown

CVE-2015-7561

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.
0
Attacker Value
Unknown

CVE-2017-1000056

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object.
0
Attacker Value
Unknown

CVE-2015-7528

Disclosure Date: April 11, 2016 (last updated November 25, 2024)
Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name.
0
Attacker Value
Unknown

CVE-2016-1905

Disclosure Date: February 03, 2016 (last updated November 25, 2024)
The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.
0
Attacker Value
Unknown

CVE-2016-1906

Disclosure Date: February 03, 2016 (last updated November 25, 2024)
Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.
0