Vulnerabilities > Linuxfoundation > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-06-03 CVE-2021-32662 Unspecified vulnerability in Linuxfoundation Backstage
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs.
network
low complexity
linuxfoundation
6.5
2021-04-30 CVE-2021-31232 Unspecified vulnerability in Linuxfoundation Cortex
The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.enable-api is used.
local
low complexity
linuxfoundation
5.5
2021-04-06 CVE-2021-29136 Improper Input Validation vulnerability in multiple products
Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that causes symlink traversal when "umoci unpack" or "umoci raw unpack" is used.
local
low complexity
linuxfoundation sylabs CWE-20
5.5
2021-03-10 CVE-2021-21334 In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) that share the same image may receive incorrect environment variables, including values that are defined for other containers.
network
high complexity
linuxfoundation fedoraproject
6.3
2021-03-09 CVE-2021-21369 Unspecified vulnerability in Linuxfoundation Besu
Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java.
network
low complexity
linuxfoundation
6.5
2021-02-02 CVE-2020-29662 Cleartext Transmission of Sensitive Information vulnerability in Linuxfoundation Harbor
In Harbor 2.0 before 2.0.5 and 2.1.x before 2.1.2 the catalog’s registry API is exposed on an unauthenticated path.
network
low complexity
linuxfoundation CWE-319
5.3
2020-12-16 CVE-2020-26273 Command Injection vulnerability in Linuxfoundation Osquery
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework.
local
low complexity
linuxfoundation CWE-77
5.2
2020-12-01 CVE-2020-15257 containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows.
local
low complexity
linuxfoundation fedoraproject debian
5.2
2020-10-16 CVE-2020-15157 Insufficiently Protected Credentials vulnerability in multiple products
In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability.
network
high complexity
linuxfoundation canonical debian CWE-522
6.1
2020-09-30 CVE-2020-13794 Missing Authorization vulnerability in Linuxfoundation Harbor
Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.
network
low complexity
linuxfoundation CWE-862
4.3