Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
–

151 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.3)0.31%—Openfeature OperatorAI17/9/202624/9/2026
The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can use the openfeature.dev/featureflagsource annotation with NAMESPACE/NAME syntax to reference a FeatureFlagSource or InProcessConfiguration in another…
Pendiente de análisisMedia (5.5)0.19%—Hawtio OperatorAI15/9/202617/9/2026
A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and written to the operator's standard output. Operator logs are typically forwarded to…
Pendiente de análisisMedia (6.3)0.49%—Hawtio OperatorAI15/9/202616/9/2026
A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without validation or authorization checks. A namespace edit user, who normally cannot set…
Pendiente de análisisAlta (7.7)0.46%—Opentelemetry OperatorAI14/9/202625/9/2026
The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor endpoint's bearerTokenFile value as…
AplazadaAlta (7.7)0.21%—Redhat OpenshiftAIOpenai OperatorAI9/9/20269/9/2026
A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended,…
RechazadaSin puntuar——Hawtio-operatorAI8/9/202621/9/2026
Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
Pendiente de análisisCrítica (9.9)0.39%—Hawtio-operatorAIRedhat OpenshiftAI8/9/20268/9/2026
A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole…
Pendiente de análisisAlta (8.2)0.42%—Hawtio OperatorAI8/9/20268/9/2026
A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The…
Pendiente de análisisAlta (7.7)0.31%—IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI4/9/202610/9/2026
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an…
Pendiente de análisisCrítica (9.6)0.21%—IBM Observability With Instana AgentAIIBM Instana Agent OperatorAI4/9/20268/9/2026
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace…
Pendiente de análisisAlta (7.7)0.53%—Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators SubscriptionAI20/8/202628/8/2026
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch…
Pendiente de análisisCrítica (9.9)0.62%—Multicloud-operators SubscriptionAI20/8/202628/8/2026
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount…
Pendiente de análisisAlta (8)0.72%—Acm-operator-bundleAI19/8/20268/9/2026
A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote…
Pendiente de análisisAlta (7.7)0.60%—Mce-operator-bundleAI19/8/202629/9/2026
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during…
Pendiente de análisisCrítica (9.9)0.55%—Search-v2-operatorAI19/8/202627/8/2026
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive…
Pendiente de análisisCrítica (9.1)0.71%—Search-v2-operatorAI19/8/202627/8/2026
A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation. By exploiting this, an attacker can mount arbitrary secrets into a…
Pendiente de análisisMedia (6.5)0.58%—Submariner-operatorAI18/8/202629/9/2026
A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters' endpoint information. Consequently, an…
Pendiente de análisisMedia (4.4)0.35%—Submariner-operatorAIRedhat Advanced Cluster Management FOR KubernetesAI18/8/20263/9/2026
A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker…
Pendiente de análisisMedia (5.4)0.39%—Submariner OperatorAI18/8/20263/9/2026
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be accessed by unauthorized parties. Such…
Pendiente de análisisAlta (8.8)0.16%—Search-v2-operatorAI17/8/202627/8/2026
A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this service account, they could exploit this to achieve `system:masters`…
Pendiente de análisisCrítica (9.9)0.69%—Multicloud-operators SubscriptionAI17/8/202629/9/2026
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to deploy resources into any namespace with the…
Pendiente de análisisCrítica (9.6)0.47%—Hashicorp Vault Secrets OperatorAI13/8/202628/8/2026
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a…
Pendiente de análisisAlta (7.7)0.48%—Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators ChannelAI12/8/202627/8/2026
A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel…
Pendiente de análisisAlta (7.7)0.48%—Multicloud-operators SubscriptionAI12/8/202627/8/2026
A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret…
Pendiente de análisisMedia (6.4)0.33%—Multicloud-operators ChannelAI12/8/20265/9/2026
A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in…