Kubernetes
39 known vulnerabilities
Top Products
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for crit
An incorrect authorization vulnerability exists in Esri Portal for ArcGIS 11.4, 11.5 and 12.0 on Windows, Linux and Kube
A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject config
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotati
A vulnerability exists in F5 BIG-IP Container Ingress Services that may allow excessive permissions to read cluster secr
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-cont
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can res
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub
The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is e
The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub
In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (r
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $
In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfigurat
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to t
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for rea
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM
In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate cert
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handli
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secre
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath
Default access permissions for Persistent Volumes (PVs) created by the Kubernetes Azure cloud provider in versions 1.6.0
Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the
Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulti
Frequently Asked Questions
How many CVEs affect Kubernetes?
Kubernetes has 39 CVE records in our database, including 5 critical and 15 high severity vulnerabilities.
What are the most severe Kubernetes vulnerabilities?
Kubernetes has 5 critical severity (CVSS 9.0+) and 15 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Kubernetes vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Kubernetes products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Kubernetes Vulnerabilities
CyberStrike scans your infrastructure for Kubernetes vulnerabilities and provides real-time remediation guidance.
Get Started