VulnSea

advanced_cluster_management_for_kubernetes vulnerabilities

CVEs whose affected-version data names the advanced_cluster_management_for_kubernetes package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

100 CVEsRSS

CVE-2024-51744Low· 3.1
1y ago

golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt (CVE-2024-517…

A flaw was found in the golang-jwt package. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are not checking errors in the way they should be. Especially, if a token is both expired and in…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4.16EPSS 0.51%via CSAF
CVE-2023-0594High· 7.3
3y ago

grafana: cross site scripting (CVE-2023-0594)

A flaw was found in the grafana package. This flaw allows a malicious user with the ability to introduce trace data to provide a JavaScript that changes the password for the user viewing the trace view (this could be an admin) to a known p…

▾ TwilightRed Hat · Red Hat Ceph Storage 5.3 ToolsEPSS 9.2%via CSAF
CVE-2022-39324Medium· 6.7
3y ago

grafana: Spoofing of the originalUrl parameter of snapshots (CVE-2022-39324)

A flaw was found in the grafana package. While creating a snapshot, an attacker may manipulate a hidden HTTP parameter to inject a malicious URL in the "Open original dashboard" button.

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.83%via CSAF
CVE-2022-41721High· 7.5
3y ago

x/net/http2/h2c: request smuggling (CVE-2022-41721)

A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead read the b…

▾ TwilightRed Hat · OpenShift Service Mesh 2.1EPSS 1.8%via CSAF
CVE-2022-23524High· 7.5⚖ disputed
3y ago

helm: Denial of service through string value parsing (CVE-2022-23524)

A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to Uncontrolled Resource Consumption. Input to functions in the _strvals_ package could cause a stack overflo…

▾ TwilightRed Hat · RHACS 4.0 for RHEL 8EPSS 0.78%via CSAF
CVE-2022-23526High· 7.5⚖ disputed
3y ago

helm: Denial of service through schema file (CVE-2022-23526)

A flaw was found in Helm, a tool for managing Charts, a pre-configured Kubernetes resources. Versions prior to 3.10.3 are subject to NULL Pointer Dereference in the_chartutil_ package that could cause a segmentation violation. The _chartut…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.86%via CSAF
CVE-2022-23525High· 7.5⚖ disputed
3y ago

helm: Denial of service through through repository index file (CVE-2022-23525)

A flaw was found in Helm. Applications that use the _repo_ package in Helm SDK to parse an index file may suffer a denial of service when that input causes a panic that cannot be recovered from. The Helm Client will panic with an index fil…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.14EPSS 0.86%via CSAF
CVE-2022-39307Medium· 5.3
3y ago

grafana: User enumeration via forget password (CVE-2022-39307)

An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.

▾ SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.75%via CSAF
CVE-2022-3064High· 7.5
4y ago

go-yaml: Improve heuristics preventing CPU/memory abuse by parsing malicious or large YAML documents (CVE-2022-3064)

A flaw was found in go-yaml. This issue causes the consumption of excessive amounts of CPU or memory when attempting to parse a large or maliciously crafted YAML document.

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 1.7%via CSAF
CVE-2020-14040High· 7.5
6y ago

golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040)

A denial of service vulnerability was found in the golang.org/x/text library. A library or application must use one of the vulnerable functions, such as unicode.Transform, transform.String, or transform.Byte, to be susceptible to this vuln…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.6EPSS 1.8%via CSAF
advanced_cluster_management_for_kubernetes vulnerabilities (CVEs) — page 4 · VulnSea