Weaveworks Weave vulnerabilities
2 known vulnerabilities affecting weaveworks/weave.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2019-3462P3HIGHCVSS 8.1fixed in 2.6.32019-01-28
CVE-2019-3462 [HIGH] CWE-350 CVE-2019-3462: Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and ea
Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.
nvd
CVE-2020-26278P3HIGHCVSS 8.0fixed in 2.8.02021-01-20
CVE-2020-26278 [HIGH] CWE-250 CVE-2020-26278: Weave Net is open source software which creates a virtual network that connects Docker containers ac
Weave Net is open source software which creates a virtual network that connects Docker containers across multiple hosts and enables their automatic discovery. Weave Net before version 2.8.0 has a vulnerability in which can allow an attacker to take over any host in the cluster. Weave Net is supplied with a manifest that runs pods on every node in a Ku
nvd