Products: 4
    Vulnerabilities: 8
    Known Exploited: 0
    0
    Critical Level Threats
    5
    High Level Threats
    2
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-38495

    Crossplane vulnerable to possible image tampering from missing image validation for Packages

    Last Modified: Nov 21, 2024
    Published: Jul 27, 2023

    CVE-2023-37900

    Crossplane vulnerable to denial of service from large image

    Last Modified: Nov 21, 2024
    Published: Jul 27, 2023

    CVE-2021-27099

    In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the issuance of an arbitrary SPIFFE ID within the same trust domain, if the attacker controls the value of an EC2 tag prior to attestation, and the attestor is configured for agent ID templating where the tag value is the last element in the path. This issue has been fixed in SPIRE versions 0.11.3 and 0.12.1

    Last Modified: Nov 21, 2024
    Published: Mar 05, 2021

    CVE-2021-27098

    In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPIRE Server’s Legacy Node API can result in the possible issuance of an X.509 certificate with a URI SAN for a SPIFFE ID that the agent is not authorized to distribute. Proper controls are in place to require that the caller presents a valid agent certificate that is already authorized to issue at least one SPIFFE ID, and the requested SPIFFE ID belongs to the same trust domain, prior to being able to trigger this vulnerability. This issue has been fixed in SPIRE versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1.

    Last Modified: Nov 21, 2024
    Published: Mar 05, 2021

    CVE-2020-8659

    envoy: Excessive CPU and/or memory usage when proxying HTTP/1.1

    Last Modified: Nov 21, 2024
    Published: Mar 03, 2020
    Items Per Page
    Cncf Vulnerabilities & Security CVEs | CVE-DB