Vulnerabilities

Last updated 31 minutes ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
github.com/kcp-dev/kcp kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace Critical 9.9 10 days ago 3 hours ago
github.com/kcp-dev/kcp kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp Unknown 3 hours ago 3 hours ago
github.com/kcp-dev/kcp kcp's cache server is accessible without authentication or authorization checks High Risk 8.2 5 months ago 18 days ago
github.com/kcp-dev/kcp kcp's cache server is accessible without authentication or authorization checks in github.com/kcp-dev/kcp Unknown 3 months ago 2 months ago
github.com/kcp-dev/kcp kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace in github.com/kcp-dev/kcp Unknown 11 months ago 6 months ago
github.com/kcp-dev/kcp kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace in github.com/kcp-dev/kcp Unknown 1 year ago 6 months ago
github.com/kcp-dev/kcp kcp's impersonation allows access to global administrative groups in github.com/kcp-dev/kcp Unknown 1 year ago 6 months ago
github.com/kcp-dev/kcp kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace Low Risk 3.0 1 year ago 11 months ago
github.com/kcp-dev/kcp kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace Critical 9.6 1 year ago 1 year ago
github.com/kcp-dev/kcp kcp's impersonation allows access to global administrative groups Medium Risk 6.4 1 year ago 1 year ago