Known Vulnerabilities for products from Mirantis
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Mirantis".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-0484 json | Lack of validation of URLs causes Mirantis Container Cloud Lens Extension before v3.1.1 to open external programs other than ... | 8.8 - HIGH | 2022-02-04 | 2022-02-09 |
| CVE-2022-0270 json | Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigne... | 8.8 - HIGH | 2022-01-25 | 2023-07-21 |
| CVE-2021-44458 json | Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could ... | 9.6 - CRITICAL | 2022-01-10 | 2022-08-09 |
| CVE-2021-23218 json | When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abu... | 7.5 - HIGH | 2022-01-10 | 2022-01-18 |
| CVE-2021-23154 json | In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments... | 7.8 - HIGH | 2022-01-10 | 2022-01-18 |