Weaveworks Weave-Gitops vulnerabilities
3 known vulnerabilities affecting weaveworks/weave-gitops.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-23508HIGHCVSS 7.8≤ 0.11.02023-01-09
CVE-2022-23508 [HIGH] CWE-284 CVE-2022-23508: Weave GitOps is a simple open source developer platform for people who want cloud native application
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could allow a local user or process to alter a Kubernetes cluster's resources. GitOps run has a local S3 bucket which it uses for synchronizing files that are later applied against a
nvd
CVE-2022-23509MEDIUMCVSS 6.0≤ 0.11.02023-01-09
CVE-2022-23509 [MEDIUM] CWE-200 CVE-2022-23509: Weave GitOps is a simple open source developer platform for people who want cloud native application
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. GitOps run has a local S3 bucket which it uses for synchronizing files that are later applied against a Kubernetes cluster. The communication between GitOps Run and the local S3 bucket is not encrypted. This al
nvd
CVE-2022-31098HIGHCVSS 7.5fixed in 0.8.1-rc.62022-06-27
CVE-2022-31098 [HIGH] CWE-532 CVE-2022-31098: Weave GitOps is a simple open source developer platform for people who want cloud native application
Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging of Weave GitOps could allow an authenticated remote attacker to view sensitive cluster configurations, aka KubeConfg, of registered Kubernetes clusters, including the service accoun
nvd