Vulnerabilities > Kubernetes > Kubernetes > 1.21.2

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2023-5528 A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes.
network
low complexity
kubernetes fedoraproject
8.8
2023-10-31 CVE-2023-3676 Improper Input Validation vulnerability in Kubernetes
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes.
network
low complexity
kubernetes CWE-20
8.8
2023-10-31 CVE-2023-3955 Improper Input Validation vulnerability in Kubernetes
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes.
network
low complexity
kubernetes CWE-20
8.8
2023-07-03 CVE-2023-2727 Unspecified vulnerability in Kubernetes
Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers.
network
low complexity
kubernetes
6.5
2023-07-03 CVE-2023-2728 Unspecified vulnerability in Kubernetes
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers.
network
low complexity
kubernetes
6.5
2023-06-16 CVE-2023-2431 A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement.
local
low complexity
kubernetes fedoraproject
5.5
2023-03-01 CVE-2022-3162 Path Traversal vulnerability in Kubernetes
Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization.
network
low complexity
kubernetes CWE-22
6.5
2023-03-01 CVE-2022-3294 Unspecified vulnerability in Kubernetes
Users may have access to secure endpoints in the control plane network.
network
low complexity
kubernetes
8.8
2021-09-20 CVE-2021-25741 Files or Directories Accessible to External Parties vulnerability in Kubernetes
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
network
low complexity
kubernetes CWE-552
5.5