Skip to content

Latest commit

 

History

History
15 lines (14 loc) · 1.42 KB

advisories.md

File metadata and controls

15 lines (14 loc) · 1.42 KB

Security Advisories

  • 0013: Mirantis Container Products and CVE-2024-41110: Not Vulnerable
  • 0012: Mirantis Container Products and CVE-2024-3094: Not Vulnerable
  • 0011: Mirantis Kubernetes Engine (MKE) and CVE-2024-21626: Understanding the Potential Impact and Mitigation
  • 0010: MCR: runc process.cwd and leaked fds container breakout
  • 0009: MCR: Encrypted overlay network with a single endpoint is unauthenticated
  • 0008: MCR: Encrypted overlay network traffic may be unencrypted
  • 0007: MCR: Encrypted overlay network may be unauthenticated
  • 0006: MCR: The Swarm VXLAN port may be exposed to attack due to ambiguous documentation
  • 0005: Improper URL Validation causes MCC Lens Extension to open external programs
  • 0004: Improper header sanitization in bored-agent causes escalation of privilege
  • 0003: Command injection in Lens causes arbitrary code execution when malicious custom helm chart configuration provided
  • 0002: Memory Leak in Mirantis Container Runtime (MCR) running in FIPS mode causes a Denial of Service (DoS)
  • 0001: Lack of websocket authentication in Lens causes remote code execution when visiting a malicious website