Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.520 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 177 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Search results for: kubernetes

Displaying 1 - 25 results out of 58

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Kubernetes API Server - YAML Parsing DoS (Billion Laughs)Network Scanner

High(7.5)

No
Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-tls-match-cn` AnnotationNetwork Scanner

High(8.8)

No
Ingress-Nginx Controller - Configuration Injection via Unsanitized Mirror AnnotationsNetwork Scanner

High(8.8)

No
Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-url` AnnotationNetwork Scanner

High(8.8)

No
Ingress-Nginx Controller - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Overview Kubernetes Resource ReportNetwork Scanner
N/A
No
Kubernetes Fake Ingress CertificateNetwork Scanner
N/A
No
Kubernetes Local Cluster Web View PanelNetwork Scanner

Medium(6.5)

No
Kube State Metrics ExposureNetwork Scanner
N/A
No
Kubernetes etcd Keys - ExposureNetwork Scanner
N/A
No
Kubernetes Kustomize ConfigurationNetwork Scanner

Medium(5.3)

No
Kubernetes Pods - API Discovery & Remote Code ExecutionNetwork Scanner
N/A
No
Rancher Default LoginNetwork Scanner

High(8.3)

No
Etcd Server - Unauthenticated AccessNetwork Scanner
N/A
No
Kubernetes Exposed MetricsNetwork Scanner
N/A
No
Etcd Remote Read Access EventKubernetes Scanner
N/A
No
Kubectl proxy ExposedKubernetes Scanner
N/A
No
Dashboard ExposedKubernetes Scanner
N/A
No
Anonymous AuthenticationKubernetes Scanner
N/A
No
CVE-2018-1002105 - Privilege EscalationKubernetes Scanner
N/A
No
Specific Unauthenticated Access to Kubernetes APIKubernetes Scanner
N/A
No
Insecure (HTTP) access to Kubernetes APIKubernetes Scanner
N/A
No
Unauthenticated Kubernetes API AccessKubernetes Scanner
N/A
No
CVE-2019-11247 - Arbitrary Access To Cluster Scoped ResourcesKubernetes Scanner
N/A
No
CVE-2019-1002100 - Denial of Service to Kubernetes API ServerKubernetes Scanner
N/A
No