Vulnerabilities > Kubernetes > High

DATE CVE VULNERABILITY TITLE RISK
2023-09-24 CVE-2023-1260 An authentication bypass vulnerability was discovered in kube-apiserver.
network
high complexity
kubernetes redhat
8.0
2023-05-24 CVE-2021-25749 Unspecified vulnerability in Kubernetes
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.
local
low complexity
kubernetes
7.8
2023-05-24 CVE-2023-1944 Use of Hard-coded Credentials vulnerability in Kubernetes Minikube
This vulnerability enables ssh access to minikube container using a default password.
local
low complexity
kubernetes CWE-798
7.8
2023-03-01 CVE-2022-3294 Unspecified vulnerability in Kubernetes
Users may have access to secure endpoints in the control plane network.
network
low complexity
kubernetes
8.8
2022-06-07 CVE-2022-1708 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API.
network
low complexity
kubernetes fedoraproject redhat CWE-770
7.5
2022-05-06 CVE-2021-25745 Improper Input Validation vulnerability in Kubernetes Ingress-Nginx
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller.
network
low complexity
kubernetes CWE-20
8.1
2022-05-06 CVE-2021-25746 Improper Input Validation vulnerability in Kubernetes Ingress-Nginx
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller.
network
low complexity
kubernetes CWE-20
7.1
2019-10-17 CVE-2019-11253 XML Entity Expansion vulnerability in multiple products
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable.
network
low complexity
kubernetes redhat CWE-776
7.5
2019-04-02 CVE-2019-9946 Always-Incorrect Control Flow Implementation vulnerability in multiple products
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes.
network
low complexity
kubernetes cncf netapp CWE-670
7.5
2019-01-03 CVE-2018-18264 Missing Authentication for Critical Function vulnerability in Kubernetes Dashboard
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
network
low complexity
kubernetes CWE-306
7.5