Vulnerabilities > Kyma Project

DATE CVE VULNERABILITY TITLE RISK
2021-12-14 CVE-2021-38182 Improper Encoding or Escaping of Output vulnerability in Kyma-Project Kyma
Due to insufficient input validation of Kyma, authenticated users can pass a Header of their choice and escalate privileges which can completely compromise the cluster.
network
low complexity
kyma-project CWE-116
8.8
2021-08-10 CVE-2021-33708 Improper Input Validation vulnerability in Kyma-Project Kyma
Due to insufficient input validation in Kyma, authenticated users can pass a Header of their choice and escalate privileges.
network
low complexity
kyma-project CWE-20
8.8