Mirantis

First CVE: Jan 10, 2022Active for: 5 years
5
CVEs Published
More CVEs Published than 15% of tracked CNAs
5.0
Avg CVEs / Year
More Avg CVEs / Year than 32% of tracked CNAs
8.5
Avg CVSS Score
Higher Avg CVSS Score than 94% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Mirantis as a CNA, 100.0% affect products that Mirantis develops as a vendor.

100.0%
Self-reported: 5Third-party: 0

Of all the CVEs published that affect products developed by Mirantis, 100.0% are self-published by Mirantis as a CNA.

100.0%
Self-published: 5Published by other CNAs: 0

Trends Over Time

The number and severity of CVEs published by Mirantis over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2022
4 years ago
Most Recent CVE
Feb 4, 2022
1,631 days ago

Top CVEs

All CVEs published by Mirantis as a CNA, regardless of affected vendor or product.

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to
Jan 10, 20229.629NONO
Lack of validation of URLs causes Mirantis Container Cloud Lens Extension before v3.1.1 to open external programs other than the default browser to perform sign on to a new cluster
Feb 4, 20228.827NONO
When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service.
Jan 10, 20227.525NONO
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments
Jan 10, 20227.825NONO
Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigned user name and groups.
Jan 25, 20228.822NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA5 CVEs
Severity distribution among all CVEs352,231 CVEs
HighCritical
Attack Vector
Local1 (20.0%)
Network4 (80.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (40.0%)
Unknown0 (0.0%)
Required3 (60.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None4 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Mirantis as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Mirantis as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs