Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Xingxing Xia

#20081of 53,635
12.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2024-16834
4.9
2024-11-15
Unknown · Oauth-Server · CVE-2024-11217
**Name of the Vulnerable Software and Affected Versions** OAuth-server (affected versions not specified) **Description** A weakness was found in the OAuth-server, where it logs the OAuth2 client secret when the logLevel is set to Debug or higher for certain login options, including OIDC, GitHub, GitLab, and Google IDPs. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2023-16844
8.0
2023-09-24
Kubernetes · Kube-Apiserver · CVE-2023-1260
**Name of the Vulnerable Software and Affected Versions** kube-apiserver (affected versions not specified) **Description** An authentication bypass issue was discovered in kube-apiserver, allowing a remote, authenticated attacker with `update, patch` permissions on the `pods/ephemeralcontainers` subresource to potentially evade SCC admission restrictions. This could enable them to gain control of a privileged pod by creating a new pod or patching an existing one they have access to. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.