Src |
Date (GMT) |
Titre |
Description |
Tags |
Stories |
Notes |
 |
2022-02-04 10:43:31 |
Argo CD vulnerability leaks sensitive info from Kubernetes apps (lien direct) |
A vulnerability in Argo CD, used by thousands of orgs for deploying applications to Kubernetes, can be leveraged in attacks to disclose sensitive information such as passwords and API keys. [...] |
Vulnerability
|
Uber
|
|
 |
2022-01-25 11:56:28 |
Linux kernel bug can let hackers escape Kubernetes containers (lien direct) |
A vulnerability affecting Linux kernel and tracked as CVE-2022-0185 can be used to escape Kubernetes containers, giving access to resources on the host system. [...] |
Vulnerability
|
Uber
|
|
 |
2022-01-02 09:48:35 |
(Déjà vu) Uber ignores vulnerability that lets you send any email from Uber.com (lien direct) |
A vulnerability in Uber's email system allows just about anyone to send emails on behalf of Uber. Uber is aware of the flaw but has decided not to fix it for now. [...] |
Vulnerability
|
Uber
Uber
|
|
 |
2022-01-02 09:48:35 |
Uber dismisses vulnerability that lets you email anyone as Uber! (lien direct) |
A vulnerability in Uber's email system allows just about anyone to send emails on behalf of Uber. Uber is aware of the flaw but has decided not to fix it. [...] |
Vulnerability
|
Uber
Uber
|
|
 |
2020-12-08 09:20:00 |
All Kubernetes versions affected by unpatched MiTM vulnerability (lien direct) |
The Kubernetes Product Security Committee has provided advice on how to temporarily block attackers from exploiting a vulnerability that could enable them to intercept traffic from other pods in multi-tenant Kubernetes clusters in man-in-the-middle (MiTM) attacks. [...] |
Vulnerability
|
Uber
|
|
 |
2019-02-11 14:10:01 |
RunC Vulnerability Gives Attackers Root Access on Docker, Kubernetes Hosts (lien direct) |
A container breakout security flaw found in the runc container runtime allows malicious containers to overwrite the host runc binary and gain root-level code execution on the host machine. [...] |
Vulnerability
|
Uber
|
|
 |
2018-12-04 11:12:03 |
Kubernetes Updates Patch Critical Privilege Escalation Bug (lien direct) |
A critical vulnerability in Kubernetes open-source system for handling containerized applications can enable an attacker to gain full administrator privileges on Kubernetes compute nodes. [...] |
Vulnerability
|
Uber
|
|