(RHSA-2023:0631) Moderate: RHSA: Submariner 0.14 – bug fix and security updates

Submariner enables direct networking between pods and services on different Kubernetes clusters that are either on-premises or in the cloud. For more information about Submariner, see the Submariner o ...

Continue Reading

CVSS3 - CRITICAL

CVSS2 - MEDIUM

Vulnerability in OpenSSL – Use-after-free following BIO_new_NDEF

The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities ...

Continue Reading
Vulnerability in OpenSSL – NULL dereference during PKCS7 data verification

A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but ...

Continue Reading
Insertion of Sensitive Information into Log File

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - LOW

Insertion of Sensitive Information into Log File

In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - LOW

Insertion of Sensitive Information into Log File

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - LOW

Web beacons on websites and in e-mail

![](https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2023/02/06085301/sl-book-page-beacon-blue-990x400.jpg) There is a vast number of [trackers](), which gather information about user ...

Continue Reading
Sensitive Information leak via Log File in Kubernetes

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This ...

Continue Reading

CVSS3 - MEDIUM

CVSS2 - LOW

Back to Main

Subscribe for the latest news: