Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.44% | — | Open Cluster Management Multicluster Observability AddonAIOpen Cluster Management Addon FrameworkAI | 18/9/2026 | 21/9/2026 | A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensitive operational information, such as goroutine, heap, and command-line details,… | |
| Pendiente de análisis | Crítica (9.9) | 0.49% | — | Open Cluster Management Managedcluster Import ControllerAI | 17/8/2026 | 29/9/2026 | A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to… | |
| Pendiente de análisis | Crítica (9.9) | 0.70% | — | Argoproj ArgocdAIOpen Cluster Management Multicloud IntegrationsAI | 12/8/2026 | 27/8/2026 | A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary… | |
| Aplazada | Alta (7.5) | 0.44% | — | Linuxfoundation Open Cluster ManagementAI | 17/12/2024 | 17/6/2026 | A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-manager or klusterlet deployments. The cluster-manager deployment uses a service account with the same name "cluster-manager" which is bound to a ClusterRole also named "cluster-manager", which… | |
| Modificada | Media (6.7) | 0.20% | — | Linuxfoundation Open Cluster Management | 24/4/2023 | 17/6/2026 | A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration-controller or cluster-manager deployments. A malicious user can take advantage of this and bind the cluster-admin to any service account or using the service account to list all… |