« Volver al listado

External-secrets

External-secrets External Secrets Operator: vulnerabilidades y CVE

External-secrets External Secrets Operator tiene 8 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses5
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-42876Media (4.9)0.26%—11 may 2026
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.1, a user who only has permission to create ExternalSecret resources can…
CVE-2026-42875Media (5.3)0.37%—11 may 2026
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.0, Namespaced SecretStore resources that used CAProvider with type…
CVE-2026-34984Alta (7.1)0.45%—14 abr 2026
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Versions 2.2.0 and below contain a vulnerability in runtime/template/v2/template.go…
CVE-2026-22822Crítica (9.3)0.19%—21 ene 2026
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the `getSecretKey` template…
CVE-2025-62159Alta (8.7)0.30%—10 oct 2025
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. A vulnerability was discovered in the BeyondTrust provider implementation for External…
CVE-2025-55196Alta (7.1)0.36%—13 ago 2025
External Secrets Operator is a Kubernetes operator that integrates external secret management systems. From version 0.15.0 to before 0.19.2, a vulnerability was discovered where the List() calls for Kubernetes Secret…
CVE-2024-45041Alta (8.8)0.59%—9 sept 2024
External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a…
CVE-2024-36540Crítica (9.8)0.42%—24 jul 2024
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System2
  2. T1210 Exploitation of Remote Services2
  3. T1068 Exploitation for Privilege Escalation1
  4. T1078 Valid Accounts1
  5. T1190 Exploit Public-Facing Application1
  6. T1552.007 Container API1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.