Vulnerabilities in Tigera
9 resultsVexday analysis
A Tigera registra 6 CVEs na base, com 3 publicadas nos últimos 90 dias, indicando atividade recente de descobertas; nenhuma está sob exploração ativa (KEV) e não há críticas CVSS, reduzindo urgência operacional imediata. A fraqueza predominante é exposição de informações sensíveis (CWE-532), sugerindo risco de vazamento de dados em configurações inadequadas; ainda assim, o perfil geral é de baixa ao moderado, sem vulnerabilidades críticas não mitigadas.
CVE-2023-41378HIGHCalico Typha hangs during unclean TLS handshakeEPSS 0.7%CVE-2022-28224MEDIUMCalico and Calico Enterprise may be vulnerable to route hijacking with the floating IP featureEPSS 0.6%CVE-2026-41184MEDIUMServiceAccount token disclosure via install-cni container logsEPSS 0.5%CVE-2026-6540HIGHL7 policy bypass via unnormalized HTTP path matchingEPSS 0.4%CVE-2026-41186MEDIUMUnauthenticated Go pprof exposure in Calico debug serverEPSS 0.3%CVE-2026-41185MEDIUMServiceAccount token disclosure via Azure IPAM CNI plugin logsEPSS 0.3%CVE-2026-6720HIGHCalicoctl leaks cluster credentials to stderr when verbose logging is enabledEPSS 0.2%CVE-2026-41187MEDIUMCalico Tier Authorization Bypass via DeleteCollectionEPSS 0.2%CVE-2024-33522MEDIUMPrivilege escalation in Calico CNI install binaryEPSS 0.2%