Mirantis
First CVE: Jan 10, 2022Active for: 5 years
5
CVEs Published
More CVEs Published than 15% of tracked CNAs
5.0
Avg CVEs / Year
More Avg CVEs / Year than 32% of tracked CNAs
8.5
Avg CVSS Score
Higher Avg CVSS Score than 94% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Mirantis as a CNA, 100.0% affect products that Mirantis develops as a vendor.
100.0%
Self-reported: 5Third-party: 0
Of all the CVEs published that affect products developed by Mirantis, 100.0% are self-published by Mirantis as a CNA.
100.0%
Self-published: 5Published by other CNAs: 0
Trends Over Time
The number and severity of CVEs published by Mirantis over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2022
4 years ago
Most Recent CVE
Feb 4, 2022
1,631 days ago
Top CVEs
All CVEs published by Mirantis as a CNA, regardless of affected vendor or product.
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44458CRITICAL Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to | Jan 10, 2022 | 9.6 | 29 | NO | NO |
CVE-2022-0484HIGH Lack of validation of URLs causes Mirantis Container Cloud Lens Extension before v3.1.1 to open external programs other than the default browser to perform sign on to a new cluster | Feb 4, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-23218HIGH When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service. | Jan 10, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-23154HIGH In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments | Jan 10, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-0270HIGH Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigned user name and groups. | Jan 25, 2022 | 8.8 | 22 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA5 CVEs
80%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local1 (20.0%)
Network4 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (40.0%)
Unknown0 (0.0%)
Required3 (60.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None4 (80.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Mirantis as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Mirantis as a CNA — matched by CVE ID, not by organization name.