Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.309 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 177 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Search results for: kubernetes

Displaying 1 - 25 results out of 58

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
Kubernetes API Server - YAML Parsing DoS (Billion Laughs)Network Scanner

High(7.5)

0.871No
Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-tls-match-cn` AnnotationNetwork Scanner

High(8.8)

0.140.94No
Ingress-Nginx Controller - Configuration Injection via Unsanitized Mirror AnnotationsNetwork Scanner

High(8.8)

0.610.99No
Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-url` AnnotationNetwork Scanner

High(8.8)

0.450.98No
Ingress-Nginx Controller - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.911No
Overview Kubernetes Resource ReportNetwork Scanner

Medium

N/A
N/A
No
Kube State Metrics ExposureNetwork Scanner

Low

N/A
N/A
No
Kubernetes Exposed MetricsNetwork Scanner

Low

N/A
N/A
No
Kubernetes Kustomize ConfigurationNetwork Scanner

Medium(5.3)

N/A
N/A
No
Kubernetes etcd Keys - ExposureNetwork Scanner

Medium

N/A
N/A
No
Kubernetes Fake Ingress CertificateNetwork Scanner

Low

N/A
N/A
No
Rancher Default LoginNetwork Scanner

High(8.3)

N/A
N/A
No
Kubernetes Local Cluster Web View PanelNetwork Scanner

Medium(6.5)

N/A
N/A
No
Kubernetes Pods - API Discovery & Remote Code ExecutionNetwork Scanner

Critical

N/A
N/A
No
Etcd Server - Unauthenticated AccessNetwork Scanner

High

N/A
N/A
No
CVE-2019-11247 - Arbitrary Access To Cluster Scoped ResourcesKubernetes Scanner

High

N/A
N/A
No
Etcd Remote Write Access EventKubernetes Scanner

High

N/A
N/A
No
Kubectl proxy ExposedKubernetes Scanner

High

N/A
N/A
No
CVE-2018-1002105 - Privilege EscalationKubernetes Scanner

High

N/A
N/A
No
Etcd Remote Read Access EventKubernetes Scanner

High

N/A
N/A
No
Specific Unauthenticated Access to Kubernetes APIKubernetes Scanner

High

N/A
N/A
No
Insecure (HTTP) access to Kubernetes APIKubernetes Scanner

High

N/A
N/A
No
Unauthenticated Kubernetes API AccessKubernetes Scanner

High

N/A
N/A
No
Exposed Run Inside ContainerKubernetes Scanner

High

N/A
N/A
No
CVE-2019-1002100 - Denial of Service to Kubernetes API ServerKubernetes Scanner

Medium

N/A
N/A
No