cncf
Cloud & SaaSoss-project
Top products
Latest CVEs
The 8 most recently published vulnerabilities affecting cncf.
- CVE-2023-38495Crossplane vulnerable to possible image tampering from missing image validation for Packages8.3
- CVE-2023-37900Crossplane vulnerable to denial of service from large image3.4
- CVE-2021-27099In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the is...6.8
- CVE-2021-27098In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPIRE Server’s Legacy Node API can result in the possible...8.1
- CVE-2020-8664CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. trusted CA) across many resources together with the combined vali...5.3
- CVE-2020-8661CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.7.5
- CVE-2020-8659CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.7.5
- CVE-2019-9946Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPor...7.5