Vulnerabilities > Kubernetes > Kubernetes > 1.18.4

DATE CVE VULNERABILITY TITLE RISK
2021-09-20 CVE-2021-25741 Files or Directories Accessible to External Parties vulnerability in Kubernetes
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
network
low complexity
kubernetes CWE-552
5.5
2021-09-06 CVE-2021-25735 Unspecified vulnerability in Kubernetes
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook.
network
low complexity
kubernetes
6.5
2021-09-06 CVE-2021-25737 Open Redirect vulnerability in Kubernetes
A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node.
4.9
2020-12-07 CVE-2020-8566 Information Exposure Through Log Files vulnerability in Kubernetes
In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs.
local
low complexity
kubernetes CWE-532
2.1
2020-12-07 CVE-2020-8565 Information Exposure Through Log Files vulnerability in Kubernetes
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files.
local
low complexity
kubernetes CWE-532
2.1
2020-12-07 CVE-2020-8564 Information Exposure Through Log Files vulnerability in Kubernetes
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials.
local
low complexity
kubernetes CWE-532
2.1
2020-12-07 CVE-2020-8563 Information Exposure Through Log Files vulnerability in Kubernetes
In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log.
local
low complexity
kubernetes CWE-532
2.1
2020-07-23 CVE-2020-8557 Resource Exhaustion vulnerability in Kubernetes
The Kubernetes kubelet component in versions 1.1-1.16.12, 1.17.0-1.17.8 and 1.18.0-1.18.5 do not account for disk usage by a pod which writes to its own /etc/hosts file.
local
low complexity
kubernetes CWE-400
5.5
2020-07-22 CVE-2020-8559 Open Redirect vulnerability in Kubernetes
The Kubernetes kube-apiserver in versions v1.6-v1.15, and versions prior to v1.16.13, v1.17.9 and v1.18.6 are vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise.
network
low complexity
kubernetes CWE-601
6.8