Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Craig Ingram

Researcher fromStripe
#19740of 53,639
13.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2023-3615
5.5
2023-06-15
Kubelet · Kubelet · CVE-2023-2431
**Name of the Vulnerable Software and Affected Versions** Kubelet (affected versions not specified) **Description** A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field are affected by this issue, allowing the pod to run in unconfined (seccomp disabled) mode. The issue is related to insufficient input validation, which can be exploited to configure certain modules to work in an unconfined mode. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2021-4318
7.8
2021-07-13
Microsoft · Visual Studio Code · CVE-2021-34477
**Name of the Vulnerable Software and Affected Versions** Visual Studio Code (affected versions not specified) **Description** The issue is related to insecure privilege management in Visual Studio Code. Exploitation of this issue may allow an attacker to elevate their privileges. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.