CSI Driver for SMB path traversal via subDir may delete unintended directories on the SMB server
Kubernetes security advisories
All 91 advisories Kubernetes has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 9191 carry a CVE
- critical
- 1
- high
- 9
- medium
- 11
- low
- 3
- Fix in the archive
- 0of 91 matched to a release
- Oldest
- 21 Mar 20179.5 years ago
91 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productingress-nginx comment-based nginx configuration injection
CSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS server
ingress-nginx rewrite-target nginx configuration injection
ingress-nginx auth-proxy-set-headers nginx configuration injection
ingress-nginx auth-method nginx configuration injection
ingress-nginx rules.http.paths.path nginx configuration injection
ingress-nginx auth-url protection bypass
ingress-nginx Admission Controller denial of service
Credential caching in Headlamp with Helm enabled
Portworx Half-Blind SSRF in kube-controller-manager
Kubernetes C# Client: improper certificate validation in custom CA mode may lead to man-in-the-middle attacks
secrets-store-sync-controller discloses service account tokens in logs
Nodes can delete themselves by adding an OwnerReference
VM images built with Kubernetes Image Builder Nutanix or OVA providers use default credentials for Windows images if user did not override
Nodes can bypass dynamic resource allocation authorization checks
ingress-nginx controller auth secret file path traversal vulnerability
ingress-nginx controller configuration injection via unsanitized auth-url annotation
ingress-nginx controller configuration injection via unsanitized auth-tls-match-cn annotation
ingress-nginx controller configuration injection via unsanitized mirror annotations
ingress-nginx admission controller RCE escalation
GitRepo Volume Inadvertent Local Repository Access
Node Denial of Service via kubelet Checkpoint API
Command Injection affecting Windows nodes via nodes/*/logs/query API
Arbitrary command execution through gitRepo volume
VM images built with Image Builder and Proxmox provider use default credentials
VM images built with Image Builder with some providers use default credentials during builds
Ingress-nginx Annotation Validation Bypass
Network restriction bypass via race condition during namespace termination
Incorrect permissions on Windows containers logs
azure-file-csi-driver discloses service account tokens in logs
Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin
Insufficient input sanitization in in-tree storage plugin leads to privilege escalation on Windows nodes
ingress-nginx path sanitization can be bypassed
Ingress nginx annotation injection causes arbitrary command execution
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
Insufficient input sanitization on kubernetes-csi-proxy leads to privilege escalation
Insufficient input sanitization on Windows nodes leads to privilege escalation
Insufficient input sanitization on Windows nodes leads to privilege escalation
Bypass of seccomp profile enforcement
Bypassing policies imposed by the ImagePolicyWebhook and bypassing mountable secrets policy imposed by the ServiceAccount admission plugin
Bypassing policies imposed by the ImagePolicyWebhook and bypassing mountable secrets policy imposed by the ServiceAccount admission plugin
secrets-store-csi-driver discloses service account tokens in logs
Unauthorized read of Custom Resources
Node address isn't always verified when proxying
Aggregated API server can cause clients to be redirected (SSRF)
`runAsNonRoot` logic bypass for Windows containers
Ingress-nginx `path` sanitization can be bypassed with newline character
Ingress-nginx `path` can be pointed to service account token file
Ingress-nginx directive injection via annotations
Ingress-nginx custom snippets allows retrieval of ingress-nginx serviceaccount token and secrets across all namespaces
Symlink Exchange Can Allow Host Filesystem Access
Webhook redirect in kube-apiserver
Endpoint & EndpointSlice permissions allow cross-Namespace forwarding
Holes in EndpointSlice Validation Enable Host Network Hijack
Bypass of Kubernetes API Server proxy TOCTOU
Processes may panic upon receipt of malicious protobuf messages
Validating Admission Webhook does not observe some previous fields
Man in the middle using LoadBalancer or ExternalIPs
Secret leaks in kube-controller-manager when using vSphere provider
Docker config secrets leaked when file is malformed and log level >= 4
Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9
Ceph RBD adminSecrets exposed in logs when loglevel >= 4
Node disk DOS by writing to container /etc/hosts
Privilege escalation from compromised node to cluster
Node setting allows for neighboring hosts to bypass localhost boundary
Half-Blind SSRF in kube-controller-manager
IPv4 only clusters susceptible to MitM attacks via IPv6 rogue router advertisements
kube-apiserver Denial of Service vulnerability from malicious YAML payloads
Kubelet DoS via API
apiserver DoS (oom)
ingress-nginx auth-type basic annotation vulnerability
kubectl cp symlink vulnerability
Unvalidated redirect
CSI volume snapshot, cloning and resizing features can result in unauthorized volume data access or mutation
Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
Bearer tokens are revealed in logs (audit finding TOB-K8S-001)
/debug/pprof exposed on kubelet's healthz port
API server allows access to custom resources via wrong scope
Incomplete fixes for CVE-2019-1002101 and CVE-2019-11246, kubectl cp potential directory traversal
container uid changes to root after first restart or if image is already pulled to the node
rest.AnonymousClientConfig() does not remove the serviceaccount credentials from config created by rest.InClusterConfig()
`kubectl --http-cache=<world-accessible dir>` creates world-writeable cached schema files
json-patch requests can exhaust apiserver resources
proxy request handling in kube-apiserver can leave vulnerable TCP connections
smb mount security issue
Kubectl copy doesn't check for paths outside of it's destination directory.
subpath volume mount handling allows arbitrary file access in host filesystem
atomic writer volume handling allows arbitrary file deletion in host filesystem
Azure PV should be Private scope not Container scope
PodSecurityPolicy admission plugin authorizes incorrectly