Clastix develops Kubernetes-native access-control and multi-tenancy solutions, principally through Capsule and Capsule-Proxy, components designed to partition and govern cluster resources. The observed vulnerability patterns center on authentication and authorization enforcement, including improper credential validation, exposure of sensitive information to unauthorized actors, and access-control bypass conditions that are characteristic of authentication-boundary components.
The number and severity of CVEs published that impact products developed by Clastix over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48312CRITICAL capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalation vulnerability which is based on a missing check if the us | Nov 24, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-46167HIGH Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to version 0.1.3, a ServiceAccount deployed in a Tenant Namespace, when granted with `PATCH` capabilitie | Dec 2, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-23652HIGH capsule-proxy is a reverse proxy for Capsule Operator which provides multi-tenancy in Kubernetes. In versions prior to 0.2.1 an attacker with a proper authentication mechanism may | Feb 22, 2022 | 8.8 | 27 | NO | NO |
CVE-2024-42480CRITICAL Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC for etcd roles leading to some T | Aug 12, 2024 | 9.9 | 26 | NO | NO |
CVE-2023-46254MEDIUM capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used by `capsule-proxy` gives ServiceAccount tenant owners the r | Nov 6, 2023 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clastix.
Media articles that mention a CVE ID that affects a product developed by Clastix — matched by CVE ID, not by vendor name.