Groups
Conversations
All groups and messages
Send feedback to Google
Help
Training
Sign in
Groups
kubernetes-security-announce
Conversations
About
Groups keyboard shortcuts have been updated
Dismiss
See shortcuts
kubernetes-security-announce
Contact owners and managers
1–30 of 77
Mark all as read
Report group
0 selected
Tabitha Sable
Mar 24
[Security Advisory] Multiple vulnerabilities in ingress-nginx
Hello Kubernetes Community, Multiple issues have been discovered in ingress-nginx that can result in
unread,
[Security Advisory] Multiple vulnerabilities in ingress-nginx
Hello Kubernetes Community, Multiple issues have been discovered in ingress-nginx that can result in
Mar 24
Craig Ingram
Mar 20
[Security Advisory] CVE-2024-7598: Network restriction bypass via race condition during namespace termination
Hello Kubernetes Community, A security issue was discovered in Kubernetes where a malicious or
unread,
[Security Advisory] CVE-2024-7598: Network restriction bypass via race condition during namespace termination
Hello Kubernetes Community, A security issue was discovered in Kubernetes where a malicious or
Mar 20
Vellore Rajakumar, Sri Saran Balaji
Mar 13
CVE-2025-1767 GitRepo Volume Inadvertent Local Repository Access
Issue Details A security vulnerability was discovered in Kubernetes that could allow a user with
unread,
CVE-2025-1767 GitRepo Volume Inadvertent Local Repository Access
Issue Details A security vulnerability was discovered in Kubernetes that could allow a user with
Mar 13
Craig Ingram
Feb 13
[Security Advisory] CVE-2025-0426: Node Denial of Service via kubelet Checkpoint API
Hello Kubernetes Community, A security issue was discovered in Kubernetes where a large number of
unread,
[Security Advisory] CVE-2025-0426: Node Denial of Service via kubelet Checkpoint API
Hello Kubernetes Community, A security issue was discovered in Kubernetes where a large number of
Feb 13
Vellore Rajakumar, Sri Saran Balaji
Jan 15
[Security Advisory] CVE-2024-9042: Command Injection affecting Windows nodes via nodes/*/logs/query API
Hello Kubernetes Community, A security vulnerability has been discovered in Kubernetes windows nodes
unread,
[Security Advisory] CVE-2024-9042: Command Injection affecting Windows nodes via nodes/*/logs/query API
Hello Kubernetes Community, A security vulnerability has been discovered in Kubernetes windows nodes
Jan 15
Craig Ingram
11/20/24
[Security Advisory] CVE-2024-10220: Arbitrary command execution through gitRepo volume
Hello Kubernetes Community, A security vulnerability was discovered in Kubernetes that could allow a
unread,
[Security Advisory] CVE-2024-10220: Arbitrary command execution through gitRepo volume
Hello Kubernetes Community, A security vulnerability was discovered in Kubernetes that could allow a
11/20/24
Joel Smith
10/14/24
[Security Advisory] CVE-2024-9486 and CVE-2024-9594: VM images built with Kubernetes Image Builder use default credentials
Hello Kubernetes Community, A security issue was discovered in Kubernetes where an unauthorized user
unread,
[Security Advisory] CVE-2024-9486 and CVE-2024-9594: VM images built with Kubernetes Image Builder use default credentials
Hello Kubernetes Community, A security issue was discovered in Kubernetes where an unauthorized user
10/14/24
Craig Ingram
8/16/24
[Ingress-nginx Security Advisory] CVE-2024-7646: Ingress-nginx Annotation Validation Bypass
Hello Kubernetes Community, A security issue was discovered in ingress-nginx where an actor with
unread,
[Ingress-nginx Security Advisory] CVE-2024-7646: Ingress-nginx Annotation Validation Bypass
Hello Kubernetes Community, A security issue was discovered in ingress-nginx where an actor with
8/16/24
Craig Ingram
7/17/24
[Security Advisory] CVE-2024-5321: Incorrect permissions on Windows containers logs
Hello Kubernetes Community, A security issue was discovered in Kubernetes clusters with Windows nodes
unread,
[Security Advisory] CVE-2024-5321: Incorrect permissions on Windows containers logs
Hello Kubernetes Community, A security issue was discovered in Kubernetes clusters with Windows nodes
7/17/24
Rita Zhang
2
5/14/24
[Security Advisory] CVE-2024-3744: azure-file-csi-driver discloses service account tokens in logs
See the GitHub issue for more details: https://github.com/kubernetes/kubernetes/issues/124759 On Wed,
unread,
[Security Advisory] CVE-2024-3744: azure-file-csi-driver discloses service account tokens in logs
See the GitHub issue for more details: https://github.com/kubernetes/kubernetes/issues/124759 On Wed,
5/14/24
Craig Ingram
11/14/23
[Security Advisory] CVE-2023-5528: Insufficient input sanitization in in-tree storage plugin leads to privilege escalation on Windows nodes
Hello Kubernetes Community, A security issue was discovered in Kubernetes where a user that can
unread,
[Security Advisory] CVE-2023-5528: Insufficient input sanitization in in-tree storage plugin leads to privilege escalation on Windows nodes
Hello Kubernetes Community, A security issue was discovered in Kubernetes where a user that can
11/14/23
CJ Cullen
10/25/23
[Ingress-nginx Security Advisory] CVE-2023-5044: Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
Issue Details A security issue was identified in ingress-nginx where the nginx.ingress.kubernetes.io/
unread,
[Ingress-nginx Security Advisory] CVE-2023-5044: Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
Issue Details A security issue was identified in ingress-nginx where the nginx.ingress.kubernetes.io/
10/25/23
CJ Cullen
10/25/23
[Ingress-nginx Security Advisory] CVE-2023-5043: Ingress nginx annotation injection causes arbitrary command execution
Issue Details A security issue was identified in ingress-nginx where the nginx.ingress.kubernetes.io/
unread,
[Ingress-nginx Security Advisory] CVE-2023-5043: Ingress nginx annotation injection causes arbitrary command execution
Issue Details A security issue was identified in ingress-nginx where the nginx.ingress.kubernetes.io/
10/25/23
CJ Cullen
10/25/23
[Ingress-nginx Security Advisory] CVE-2022-4886: Ingress-nginx `path` sanitization can be bypassed with `log_format` directive
Issue Details A security issue was discovered in ingress-nginx where a user that can create or update
unread,
[Ingress-nginx Security Advisory] CVE-2022-4886: Ingress-nginx `path` sanitization can be bypassed with `log_format` directive
Issue Details A security issue was discovered in ingress-nginx where a user that can create or update
10/25/23
Rita Zhang
8/23/23
[Security Advisory] CVE-2023-3893: Insufficient input sanitization on kubernetes-csi-proxy leads to privilege escalation
Hello Kubernetes Community, A security issue was discovered in Kubernetes where a user that can
unread,
[Security Advisory] CVE-2023-3893: Insufficient input sanitization on kubernetes-csi-proxy leads to privilege escalation
Hello Kubernetes Community, A security issue was discovered in Kubernetes where a user that can
8/23/23
Rita Zhang
8/23/23
[Security Advisory] CVE-2023-3955: Insufficient input sanitization on Windows nodes leads to privilege escalation
Hello Kubernetes Community, A security issue was discovered in Kubernetes where a user that can
unread,
[Security Advisory] CVE-2023-3955: Insufficient input sanitization on Windows nodes leads to privilege escalation
Hello Kubernetes Community, A security issue was discovered in Kubernetes where a user that can
8/23/23
Rita Zhang
8/23/23
[Security Advisory] CVE-2023-3676: Insufficient input sanitization on Windows nodes leads to privilege escalation
Hello Kubernetes Community, A security issue was discovered in Kubernetes where a user that can
unread,
[Security Advisory] CVE-2023-3676: Insufficient input sanitization on Windows nodes leads to privilege escalation
Hello Kubernetes Community, A security issue was discovered in Kubernetes where a user that can
8/23/23
CJ Cullen
6/21/23
[kOps Security Advisory] CVE-2023-1943: Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode
Issue Details A security issue was reported in kOps with the GCP Provider running in Gossip Mode,
unread,
[kOps Security Advisory] CVE-2023-1943: Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode
Issue Details A security issue was reported in kOps with the GCP Provider running in Gossip Mode,
6/21/23
Rita Zhang
6/15/23
[Security Advisory] CVE-2023-2728: Bypassing enforce mountable secrets policy imposed by the ServiceAccount admission plugin
Hello Kubernetes Community, A security issue was discovered in Kubernetes where users may be able to
unread,
[Security Advisory] CVE-2023-2728: Bypassing enforce mountable secrets policy imposed by the ServiceAccount admission plugin
Hello Kubernetes Community, A security issue was discovered in Kubernetes where users may be able to
6/15/23
Rita Zhang
6/15/23
[Security Advisory] CVE-2023-2727: Bypassing policies imposed by the ImagePolicyWebhook admission plugin
Hello Kubernetes Community, A security issue was discovered in Kubernetes where users may be able to
unread,
[Security Advisory] CVE-2023-2727: Bypassing policies imposed by the ImagePolicyWebhook admission plugin
Hello Kubernetes Community, A security issue was discovered in Kubernetes where users may be able to
6/15/23
Vellore Rajakumar, Sri Saran Balaji
6/14/23
[Security Advisory] CVE-2023-2431: Bypass of seccomp profile enforcement
Hello Kubernetes Community, A security issue was discovered in Kubelet that allows pods to bypass the
unread,
[Security Advisory] CVE-2023-2431: Bypass of seccomp profile enforcement
Hello Kubernetes Community, A security issue was discovered in Kubelet that allows pods to bypass the
6/14/23
Monis Khan
5/25/23
[Security Advisory] CVE-2023-2878: secrets-store-csi-driver discloses service account tokens in logs
Hello Kubernetes Community, A security issue was discovered in secrets-store-csi-driver where an
unread,
[Security Advisory] CVE-2023-2878: secrets-store-csi-driver discloses service account tokens in logs
Hello Kubernetes Community, A security issue was discovered in secrets-store-csi-driver where an
5/25/23
Vellore Rajakumar, Sri Saran Balaji
4/12/23
[Security Advisory] CVE-2023-1174, CVE-2023-1944: Network port exposure and ssh access using default password
Hello Kubernetes Community, We have released minikube v1.30.0 to address two security issues in
unread,
[Security Advisory] CVE-2023-1174, CVE-2023-1944: Network port exposure and ssh access using default password
Hello Kubernetes Community, We have released minikube v1.30.0 to address two security issues in
4/12/23
CJ Cullen
1/31/23
[Kubernetes Java Client] Kubernetes Java client impacted by CVE-2022-1471
Issue Details A security issue was discovered in the Kubernetes Java client library where loading
unread,
[Kubernetes Java Client] Kubernetes Java client impacted by CVE-2022-1471
Issue Details A security issue was discovered in the Kubernetes Java client library where loading
1/31/23
Tim Allclair
11/10/22
[Security Advisory] CVE-2022-3294: Node address isn't always verified when proxying
Hello Kubernetes Community, A security issue was discovered in Kubernetes where users may have access
unread,
[Security Advisory] CVE-2022-3294: Node address isn't always verified when proxying
Hello Kubernetes Community, A security issue was discovered in Kubernetes where users may have access
11/10/22
Tim Allclair
11/10/22
[Security Advisory] CVE-2022-3162: Unauthorized read of Custom Resources
Hello Kubernetes Community, A security issue was discovered in Kubernetes where users authorized to
unread,
[Security Advisory] CVE-2022-3162: Unauthorized read of Custom Resources
Hello Kubernetes Community, A security issue was discovered in Kubernetes where users authorized to
11/10/22
Pushkar Joglekar
9/15/22
[Security Advisory] CVE-2021-25749: runAsNonRoot logic bypass for Windows containers
Hello Kubernetes Community, A security issue was discovered in Kubernetes that could allow Windows
unread,
[Security Advisory] CVE-2021-25749: runAsNonRoot logic bypass for Windows containers
Hello Kubernetes Community, A security issue was discovered in Kubernetes that could allow Windows
9/15/22
Hausler, Micah
7/11/22
[Security Advisory] CVE-2022-2385: AccessKeyID validation bypass
Hello Kubernetes Community, A security issue was discovered in aws-iam-authenticator where an allow-
unread,
[Security Advisory] CVE-2022-2385: AccessKeyID validation bypass
Hello Kubernetes Community, A security issue was discovered in aws-iam-authenticator where an allow-
7/11/22
CJ Cullen
6/10/22
[Security Advisory] CVE-2021-25748: Ingress-nginx `path` sanitization can be bypassed with newline character
Issue Details A security issue was discovered in ingress-nginx where a user that can create or update
unread,
[Security Advisory] CVE-2021-25748: Ingress-nginx `path` sanitization can be bypassed with newline character
Issue Details A security issue was discovered in ingress-nginx where a user that can create or update
6/10/22
CJ Cullen
4/22/22
[Security Advisory] CVE-2021-25746: Ingress-nginx directive injection via annotations
Issue Details A security issue was discovered in ingress-nginx where a user that can create or update
unread,
[Security Advisory] CVE-2021-25746: Ingress-nginx directive injection via annotations
Issue Details A security issue was discovered in ingress-nginx where a user that can create or update
4/22/22