Cncf
3 CVEs tracked since 2020. Since Mar 2020, none of them reached CISA KEV.
Cncf CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-03 | 3 | 0 |
Products
The products that kept showing up in Cncf's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 8 most recently published vulnerabilities affecting Cncf.
- CVE-2023-38495Crossplane vulnerable to possible image tampering from missing image validation for Packages8.3
- CVE-2023-37900Crossplane vulnerable to denial of service from large image3.4
- CVE-2021-27099In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the path provided through the agent ID templating feature, which may allow the is...6.8
- CVE-2021-27098In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the FetchX509SVID RPC of SPIRE Server’s Legacy Node API can result in the possible...8.1
- CVE-2020-8664CNCF Envoy through 1.13.0 has incorrect Access Control when using SDS with Combined Validation Context. Using the same secret (e.g. trusted CA) across many resources together with the combined vali...5.3
- CVE-2020-8661CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests.7.5
- CVE-2020-8659CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks.7.5
- CVE-2019-9946Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI 'portmap' plugin, used to setup HostPor...7.5
The record
- Peak rank
- #131 in Mar 2020
- Busiest month shown
- Mar 2020, 3 CVEs
- Months with a KEV entry
- 0 since Mar 2020
- Monthly snapshots
- 1 since 2020