Lucene search

K

Capsule Security Vulnerabilities

cve
cve

CVE-2022-46167

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to version 0.1.3, a ServiceAccount deployed in a Tenant Namespace, when granted with PATCH capabilities on its own Namespace, is able to edit it and remove the Owner Reference, breaking the reconciliation of the Capsule Ope...

8.8CVSS

8.6AI Score

0.001EPSS

2022-12-02 07:15 PM
25
cve
cve

CVE-2023-46254

capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used by capsule-proxy gives ServiceAccount tenant owners the right to list Namespaces of other tenants backed by the same owner kind and name. For example consider two tenants solar a...

4.3CVSS

4.7AI Score

0.0004EPSS

2023-11-06 07:15 PM
20