Debian Kubernetes vulnerabilities
49 known vulnerabilities affecting debian/kubernetes.
Total CVEs
49
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH11MEDIUM26LOW10
Vulnerabilities
Page 1 of 3
CVE-2019-11248P1HIGHCVSS 8.2ExploitedPoCfixed in kubernetes 1.17.4-1 (bookworm)2019
CVE-2019-11248 [HIGH] CVE-2019-11248: kubernetes - The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet ...
The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is exposed over the Kubelet's healthz port. This debugging endpoint can potentially leak sensitive information such as internal Kubelet memory addresses and configuration, or for limited denial of service. Versions prior to 1.15.0, 1.14.4, 1.13.8, a
debian
CVE-2018-1002105P1CRITICALCVSS 9.8PoCfixed in kubernetes 1.17.4-1 (bookworm)2018
CVE-2018-1002105 [CRITICAL] CVE-2018-1002105: kubernetes - In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect ha...
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authent
debian
CVE-2019-11253P2HIGHCVSS 7.5PoCfixed in kubernetes 1.17.4-1 (bookworm)2019
CVE-2019-11253 [HIGH] CVE-2019-11253: kubernetes - Improper input validation in the Kubernetes API server in versions v1.0-1.12 and...
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonym
debian
CVE-2023-3676P2HIGHCVSS 8.8fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2023
CVE-2023-3676 [HIGH] CVE-2023-3676: kubernetes - A security issue was discovered in Kubernetes where a user that can create pods...
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
Scope: local
bookworm: resolved (fixed in 1.20.5+really1.20.2-1)
bullseye: resolved (fixed in 1.20.5+really1.20.2-1)
forky: resolved (fixed i
debian
CVE-2017-1002101P2HIGHCVSS 8.8fixed in kubernetes 1.7.16+dfsg-1 (bookworm)2017
CVE-2017-1002101 [HIGH] CVE-2017-1002101: kubernetes - In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, ...
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside of the volume, including the host's filesystem.
Scope: local
bookworm: resolved (fixed in 1.7.16+dfsg-1)
bu
debian
CVE-2023-3955P3HIGHCVSS 8.8fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2023
CVE-2023-3955 [HIGH] CVE-2023-3955: kubernetes - A security issue was discovered in Kubernetes where a user that can create pods...
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
Scope: local
bookworm: resolved (fixed in 1.20.5+really1.20.2-1)
bullseye: resolved (fixed in 1.20.5+really1.20.2-1)
forky: resolved (fixed i
debian
CVE-2022-3294P3MEDIUMCVSS 6.6fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2022
CVE-2022-3294 [MEDIUM] CVE-2022-3294: kubernetes - Users may have access to secure endpoints in the control plane network. Kubernet...
Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. W
debian
CVE-2024-10220P3HIGHCVSS 8.1fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2024
CVE-2024-10220 [HIGH] CVE-2024-10220: kubernetes - The Kubernetes kubelet component allows arbitrary command execution via speciall...
The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.
Scope: local
bookworm: resolved (fixed in 1.20.5+really1.20.2-1)
bullseye: resolved (fixed in 1.20.5+really1.20.2-1)
forky: resolved (fixed in 1.20.5+really1.
debian
CVE-2023-3893P3HIGHCVSS 8.8fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2023
CVE-2023-3893 [HIGH] CVE-2023-3893: kubernetes - A security issue was discovered in Kubernetes where a user that can create pods...
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.
Scope: local
bookworm: resolved (fixed in 1.20.5+really1.20.2-1)
bullseye: resolved
debian
CVE-2021-25741P3HIGHCVSS 8.8fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2021
CVE-2021-25741 [HIGH] CVE-2021-25741: kubernetes - A security issue was discovered in Kubernetes where a user may be able to create...
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
Scope: local
bookworm: resolved (fixed in 1.20.5+really1.20.2-1)
bullseye: resolved (fixed in 1.20.5+really1.20.2-1)
forky: resolved (fixed in 1.20.5+really1.
debian
CVE-2019-11247P3HIGHCVSS 8.1fixed in kubernetes 1.17.4-1 (bookworm)2019
CVE-2019-11247 [HIGH] CVE-2019-11247: kubernetes - The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custo...
The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced. Authorizations for the resource accessed in this manner are enforced using roles and role bindings within the namespace, meaning that a user with access only to a resource in one namespace could create, view update
debian
CVE-2020-8558P3MEDIUMCVSS 5.4fixed in kubernetes 1.18.5-1 (bookworm)2020
CVE-2020-8558 [MEDIUM] CVE-2020-8558: kubernetes - The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, ...
The Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3 were found to contain a security issue which allows adjacent hosts to reach TCP and UDP services bound to 127.0.0.1 running on the node or in the node's network namespace. Such a service is generally thought to be reachable only by other processes on the same host, b
debian
CVE-2017-1000056P3CRITICALCVSS 9.8fixed in kubernetes 1.5.5+dfsg-1 (bookworm)2017
CVE-2017-1000056 [CRITICAL] CVE-2017-1000056: kubernetes - Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the Po...
Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object.
Scope: local
bookworm: resolved (fixed in 1.5.5+dfsg-1)
bullseye: resolved (fixed in 1.5.5+dfsg-1)
forky: resolved (fixed in 1.5.5+dfsg-1)
sid: resolved (fixed in 1.
debian
CVE-2016-7075P3HIGHCVSS 7.5fixed in kubernetes 1.5.5+dfsg-1 (bookworm)2016
CVE-2016-7075 [HIGH] CVE-2016-7075: kubernetes - It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly...
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
Scope: local
bookworm: resolved (fixed in 1.5.5+dfsg-1)
bullseye: resolved (fixed in 1.5.5+dfsg-1)
fork
debian
CVE-2019-9946P3LOWCVSS 7.5fixed in kubernetes 1.17.4-1 (bookworm)2019
CVE-2019-9946 [HIGH] CVE-2019-9946: golang-github-containernetworking-plugins - Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0....
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, th
debian
CVE-2022-3172P3MEDIUMCVSS 5.1fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2022
CVE-2022-3172 [MEDIUM] CVE-2022-3172: kubernetes - A security issue was discovered in kube-apiserver that allows an aggregated API...
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.
Scope: local
bookworm: resolved (fixed in 1.20.5+really1.20.2-1)
bullseye: resolved (fixed in 1.20.5+re
debian
CVE-2019-1002100P3MEDIUMCVSS 6.5fixed in kubernetes 1.17.4-1 (bookworm)2019
CVE-2019-1002100 [MEDIUM] CVE-2019-1002100: kubernetes - In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that ar...
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Se
debian
CVE-2020-8555P3MEDIUMCVSS 6.3fixed in kubernetes 1.18.2-1 (bookworm)2020
CVE-2020-8555 [MEDIUM] CVE-2020-8555: kubernetes - The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to ...
The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback serv
debian
CVE-2020-8554P3LOWCVSS 6.3fixed in kubernetes 1.31.4+ds-1 (forky)2020
CVE-2020-8554 [MEDIUM] CVE-2020-8554: kubernetes - Kubernetes API server in all versions allow an attacker who is able to create a ...
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the stat
debian
CVE-2023-2728P3MEDIUMCVSS 6.5fixed in kubernetes 1.20.5+really1.20.2-1 (bookworm)2023
CVE-2023-2728 [MEDIUM] CVE-2023-2728: kubernetes - Users may be able to launch containers that bypass the mountable secrets policy ...
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission pl
debian
1 / 3Next →