Vulnerabilities > Linuxfoundation

DATE CVE VULNERABILITY TITLE RISK
2023-05-15 CVE-2023-20726 Missing Authorization vulnerability in multiple products
In mnld, there is a possible leak of GPS location due to a missing permission check.
3.3
2023-05-11 CVE-2023-29195 Unspecified vulnerability in Linuxfoundation Vitess
Vitess is a database clustering system for horizontal scaling of MySQL through generalized sharding.
network
low complexity
linuxfoundation
4.3
2023-05-08 CVE-2023-30840 Incorrect Authorization vulnerability in Linuxfoundation Fluid
Fluid is an open source Kubernetes-native distributed dataset orchestrator and accelerator for data-intensive applications.
local
low complexity
linuxfoundation CWE-863
7.8
2023-05-08 CVE-2023-30551 Allocation of Resources Without Limits or Throttling vulnerability in Linuxfoundation Rekor
Rekor is an open source software supply chain transparency log.
network
low complexity
linuxfoundation CWE-770
7.5
2023-04-26 CVE-2023-30841 Cleartext Transmission of Sensitive Information vulnerability in Linuxfoundation Baremetal Operator
Baremetal Operator (BMO) is a bare metal host provisioning integration for Kubernetes.
local
low complexity
linuxfoundation CWE-319
5.5
2023-04-24 CVE-2023-2250 Unspecified vulnerability in Linuxfoundation Open Cluster Management
A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration-controller or cluster-manager deployments.
local
low complexity
linuxfoundation
6.7
2023-04-19 CVE-2023-22645 Improper Privilege Management vulnerability in Linuxfoundation Kubewarden-Controller
An Improper Privilege Management vulnerability in SUSE kubewarden allows attackers to read arbitrary secrets if they get access to the ServiceAccount kubewarden-controller This issue affects: SUSE kubewarden kubewarden-controller versions prior to 1.6.0.
network
low complexity
linuxfoundation CWE-269
8.8
2023-04-14 CVE-2023-29018 Unspecified vulnerability in Linuxfoundation Openfeature
The OpenFeature Operator allows users to expose feature flags to applications.
network
low complexity
linuxfoundation
8.8
2023-04-14 CVE-2023-29194 Unspecified vulnerability in Linuxfoundation Vitess
Vitess is a database clustering system for horizontal scaling of MySQL.
network
low complexity
linuxfoundation
2.7
2023-04-12 CVE-2023-30512 Incorrect Permission Assignment for Critical Resource vulnerability in Linuxfoundation Cubefs
CubeFS through 3.2.1 allows Kubernetes cluster-level privilege escalation.
network
low complexity
linuxfoundation CWE-732
6.5