CVE-2020-8558 Kubernetes Official CVE Feed 5 years 7 months ago Node setting allows for neighboring hosts to bypass localhost boundary
CVE-2020-8555 Kubernetes Official CVE Feed 5 years 8 months ago Half-Blind SSRF in kube-controller-manager
CVE-2020-10749 Kubernetes Official CVE Feed 5 years 8 months ago IPv4 only clusters susceptible to MitM attacks via IPv6 rogue router advertisements
CVE-2019-11254 Kubernetes Official CVE Feed 5 years 10 months ago kube-apiserver Denial of Service vulnerability from malicious YAML payloads
CVE-2020-8553 Kubernetes Official CVE Feed 5 years 11 months ago ingress-nginx auth-type basic annotation vulnerability
CVE-2019-11255 Kubernetes Official CVE Feed 6 years 2 months ago CSI volume snapshot, cloning and resizing features can result in unauthorized volume data access or mutation
CVE-2019-11253 Kubernetes Official CVE Feed 6 years 4 months ago Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
CVE-2019-11250 Kubernetes Official CVE Feed 6 years 5 months ago Bearer tokens are revealed in logs (audit finding TOB-K8S-001)
CVE-2019-11248 Kubernetes Official CVE Feed 6 years 5 months ago /debug/pprof exposed on kubelet's healthz port
CVE-2019-11249 Kubernetes Official CVE Feed 6 years 5 months ago Incomplete fixes for CVE-2019-1002101 and CVE-2019-11246, kubectl cp potential directory traversal
CVE-2019-11247 Kubernetes Official CVE Feed 6 years 5 months ago API server allows access to custom resources via wrong scope
CVE-2019-11245 Kubernetes Official CVE Feed 6 years 8 months ago container uid changes to root after first restart or if image is already pulled to the node
CVE-2019-11243 Kubernetes Official CVE Feed 6 years 9 months ago rest.AnonymousClientConfig() does not remove the serviceaccount credentials from config created by rest.InClusterConfig()
CVE-2019-11244 Kubernetes Official CVE Feed 6 years 9 months ago `kubectl --http-cache=<world-accessible dir>` creates world-writeable cached schema files
CVE-2019-1002100 Kubernetes Official CVE Feed 6 years 11 months ago json-patch requests can exhaust apiserver resources
CVE-2018-1002105 Kubernetes Official CVE Feed 7 years 2 months ago proxy request handling in kube-apiserver can leave vulnerable TCP connections