Garden is a niche vendor with a focused product footprint centered on a single platform, where the observed vulnerability profile clusters around untrusted deserialization, code injection, and missing authentication controls. These weakness classes reflect the parser and access-control surface of the platform itself; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Garden over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24829CRITICAL Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did not require authentication. In some operating modes thi | Apr 11, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-44392CRITICAL Garden provides automation for Kubernetes development and testing. Prior tov ersions 0.13.17 and 0.12.65, Garden has a dependency on the cryo library, which is vulnerable to code i | Oct 9, 2023 | 9.0 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Garden.
Media articles that mention a CVE ID that affects a product developed by Garden — matched by CVE ID, not by vendor name.