Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2024-56514

Disclosure Date: January 03, 2025 (last updated January 05, 2025)
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karmadactl and karmada-operator, it is possible to supply a filesystem path, or an HTTP(s) URL to retrieve the custom resource definitions(CRDs) needed by Karmada. The CRDs are downloaded as a gzipped tarfile and are vulnerable to a TarSlip vulnerability. An attacker able to supply a malicious CRD file into a Karmada initialization could write arbitrary files in arbitrary paths of the filesystem. From Karmada version 1.12.0, when processing custom CRDs files, CRDs archive verification is utilized to enhance file system robustness. A workaround is available. Someone who needs to set flag `--crd` to customize the CRD files required for Karmada initialization when using `karmadactl init` to set up Karmada can manually inspect the CRD files to check whether they contain sequences such as `../` that would alter file pa…
0
Attacker Value
Unknown

CVE-2024-56513

Disclosure Date: January 03, 2025 (last updated January 05, 2025)
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command have excessive privileges to access control plane resources. By abusing these permissions, an attacker able to authenticate as the karmada-agent to a karmada cluster would be able to obtain administrative privileges over the entire federation system including all registered member clusters. Since Karmada v1.12.0, command `karmadactl register` restricts the access permissions of pull mode member clusters to control plane resources. This way, an attacker able to authenticate as the karmada-agent cannot control other member clusters in Karmada. As a workaround, one may restrict the access permissions of pull mode member clusters to control plane resources according to Karmada Component Permissions Docs.
0
Attacker Value
Unknown

CVE-2024-34695

Disclosure Date: May 14, 2024 (last updated February 26, 2025)
WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. Due to timing, sending multiple posts simultaneously requests bypasses the cooldown validation, however are not refreshing a user's metrics more than once, due to concurrent karma updates. This issue is fixed in 0.17.4.1.
0
Attacker Value
Unknown

CVE-2022-37602

Disclosure Date: October 14, 2022 (last updated February 24, 2025)
Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.
Attacker Value
Unknown

CVE-2021-23495

Disclosure Date: February 25, 2022 (last updated February 23, 2025)
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.
Attacker Value
Unknown

CVE-2022-0437

Disclosure Date: February 05, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.
Attacker Value
Unknown

CVE-2020-7626

Disclosure Date: April 02, 2020 (last updated February 21, 2025)
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
Attacker Value
Unknown

CVE-2018-18399

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.
0
Attacker Value
Unknown

CVE-2008-6276

Disclosure Date: February 25, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allow remote authenticated administrators to execute arbitrary SQL commands via (1) a content type or (2) a voting API value.
0
Attacker Value
Unknown

CVE-2008-6275

Disclosure Date: February 25, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages.
0