Lucene search

K

Kubeedge Security Vulnerabilities

cve
cve

CVE-2022-31080

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, a large response received by the viaduct WSClient can cause a DoS from memory exhaustion. The entire body of the response is...

6.5CVSS

6.2AI Score

0.001EPSS

2022-07-11 09:15 PM
543
10
cve
cve

CVE-2022-31075

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, EdgeCore may be susceptible to a DoS attack on CloudHub if an attacker was to send a well-crafted HTTP request to /edge.crt. If....

6.5CVSS

6.2AI Score

0.001EPSS

2022-07-11 09:15 PM
30
8
cve
cve

CVE-2022-31079

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, the Cloud Stream server and the Edge Stream server reads the entire message into memory without imposing a limit on the size of....

6.5CVSS

6.2AI Score

0.001EPSS

2022-07-11 09:15 PM
42
10
cve
cve

CVE-2022-31078

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, the CloudCore Router does not impose a limit on the size of responses to requests made by the REST handler. An attacker could...

6.5CVSS

6.2AI Score

0.001EPSS

2022-07-11 09:15 PM
449
8
cve
cve

CVE-2022-31073

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, the ServiceBus server on the edge side may be susceptible to a DoS attack if an HTTP request containing a very large Body is...

7.5CVSS

7.4AI Score

0.002EPSS

2022-07-11 08:15 PM
31
8
cve
cve

CVE-2022-31074

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, several endpoints in the Cloud AdmissionController may be susceptible to a DoS attack if an HTTP request containing a very...

6.5CVSS

6.3AI Score

0.001EPSS

2022-07-11 08:15 PM
42
8
cve
cve

CVE-2022-31077

KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message response from KubeEdge can crash the CSI Driver controller server by triggering a nil-pointer dereference panic. As a...

5.7CVSS

5.4AI Score

0.001EPSS

2022-06-27 09:15 PM
48
7
cve
cve

CVE-2022-31076

KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message can crash CloudCore by triggering a nil-pointer dereference in the UDS Server. Since the UDS Server only communicates...

5.7CVSS

5.3AI Score

0.0004EPSS

2022-06-27 08:15 PM
45
3