Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.908 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Search results for: kubernetes

Displaying 1 - 25 results out of 60

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Argo Workflows - Unauthenticated DashboardNetwork Scanner

Critical

No
Headlamp Kubernetes UI PanelNetwork Scanner

Medium

No
Kubernetes API Server - YAML Parsing DoS (Billion Laughs)Network Scanner

High(7.5)

No
Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-url` AnnotationNetwork Scanner

High(8.8)

No
Ingress-Nginx Controller - Configuration Injection via Unsanitized Mirror AnnotationsNetwork Scanner

High(8.8)

No
Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-tls-match-cn` AnnotationNetwork Scanner

High(8.8)

No
Ingress-Nginx Controller - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Etcd Server - Unauthenticated AccessNetwork Scanner

High

No
Overview Kubernetes Resource ReportNetwork Scanner

Medium

No
Kube State Metrics ExposureNetwork Scanner

Low

No
Kubernetes Fake Ingress CertificateNetwork Scanner

Low

No
Kubernetes etcd Keys - ExposureNetwork Scanner

Medium

No
Kubernetes Pods - API Discovery & Remote Code ExecutionNetwork Scanner

Critical

No
Kubernetes Exposed MetricsNetwork Scanner

Low

No
Rancher Default LoginNetwork Scanner

High(8.3)

No
Kubernetes Local Cluster Web View PanelNetwork Scanner

Medium(6.5)

No
Kubernetes Kustomize ConfigurationNetwork Scanner

Medium(5.3)

No
CVE-2018-1002105 - Privilege EscalationKubernetes Scanner

High

No
Exposed Run Inside ContainerKubernetes Scanner

High

No
Etcd Remote Write Access EventKubernetes Scanner

High

No
Specific Unauthenticated Access to Kubernetes APIKubernetes Scanner

High

No
Insecure (HTTP) access to Kubernetes APIKubernetes Scanner

High

No
Unauthenticated Kubernetes API AccessKubernetes Scanner

High

No
Kubectl proxy ExposedKubernetes Scanner

High

No
CVE-2019-11247 - Arbitrary Access To Cluster Scoped ResourcesKubernetes Scanner

High

No