Vulnerabilities
Last updated 31 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace | Critical 9.9 | 10 days ago | 3 hours ago |
|
|
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp | Unknown | 3 hours ago | 3 hours ago |
|
|
kcp's cache server is accessible without authentication or authorization checks | High Risk 8.2 | 5 months ago | 18 days ago |
|
|
kcp's cache server is accessible without authentication or authorization checks in github.com/kcp-dev/kcp | Unknown | 3 months ago | 2 months ago |
|
|
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace in github.com/kcp-dev/kcp | Unknown | 11 months ago | 6 months ago |
|
|
kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace in github.com/kcp-dev/kcp | Unknown | 1 year ago | 6 months ago |
|
|
kcp's impersonation allows access to global administrative groups in github.com/kcp-dev/kcp | Unknown | 1 year ago | 6 months ago |
|
|
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace | Low Risk 3.0 | 1 year ago | 11 months ago |
|
|
kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace | Critical 9.6 | 1 year ago | 1 year ago |
|
|
kcp's impersonation allows access to global administrative groups | Medium Risk 6.4 | 1 year ago | 1 year ago |
Page 1