Linuxfoundation
Linuxfoundation Spinnaker: vulnerabilidades y CVE
Linuxfoundation Spinnaker tiene 10 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses5
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-55175 | Alta (7.5) | 1.1% | — | 10 jul 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag… |
| CVE-2026-44795 | Alta (8.8) | 1.0% | — | 10 jul 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or… |
| CVE-2026-32613 | Crítica (9.9) | 0.66% | — | 20 abr 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression Language) to process information - specifically around expected artifacts. In versions… |
| CVE-2026-32604 | Crítica (9.9) | 0.77% | — | 20 abr 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025.3.2, a bad actor can execute arbitrary commands very simply on the clouddriver pods.… |
| CVE-2025-61916 | Media (6.6) | 0.17% | — | 5 ene 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primary impact is allowing users to fetch data… |
| CVE-2023-39348 | Media (5.3) | 0.38% | — | 28 ago 2023 | Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. It's recommended to apply the patch and rotate the GitHub token used for… |
| CVE-2022-23506 | Alta (7.5) | 0.54% | — | 3 ene 2023 | Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces machine images. Rosco prior to versions 1.29.2, 1.28.4, and 1.27.3 does… |
| CVE-2021-43832 | Crítica (9.8) | 2.6% | — | 4 ene 2022 | Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creation & execution. This lets an arbitrary user with access to the gate endpoint to create a… |
| CVE-2021-39143 | Alta (7.1) | 0.34% | — | 4 ene 2022 | Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in uses of TAR files by AppEngine for deployments. This uses a utility to extract files locally for… |
| CVE-2020-9301 | Alta (8.8) | 1.5% | — | 11 dic 2020 | Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that… |