Trident
Vendor:
First CVE: Dec 5, 2018 · Active for 7 years
11
Total CVEs
More Total CVEs than 89% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Trident over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 5, 2018
7 years ago
Most Recent CVE
Oct 29, 2021
1,729 days ago
CVE Severity & Scoring
Trident11 CVEs
45%
45%
9%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (54.5%)
High5 (45.5%)
Unknown0 (0.0%)
User Interaction
None8 (72.7%)
Unknown0 (0.0%)
Required3 (27.3%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None9 (81.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1002105CRITICAL In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafte | Dec 5, 2018 | 9.8 | 85 | NO | YES |
CVE-2019-9514HIGH Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over ea | Aug 13, 2019 | 7.5 | 65 | NO | NO |
CVE-2021-34558MEDIUM The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchan | Jul 15, 2021 | 6.5 | 26 | NO | NO |
CVE-2019-11243HIGH In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, | Apr 22, 2019 | 8.1 | 26 | NO | NO |
CVE-2021-25742HIGH A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster. | Oct 29, 2021 | 7.1 | 25 | NO | NO |
CVE-2020-28366HIGH Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file | Nov 18, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-28362HIGH Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service. | Nov 18, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-29511MEDIUM The encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips, which allows an attacker to c | Dec 14, 2020 | 5.6 | 21 | NO | NO |
CVE-2020-29509MEDIUM The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to | Dec 14, 2020 | 5.6 | 21 | NO | NO |
CVE-2020-29510MEDIUM The encoding/xml package in Go versions 1.15 and earlier does not correctly preserve the semantics of directives during tokenization round-trips, which allows an attacker to craft | Dec 14, 2020 | 5.6 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Trident
Top CWEs
Versions
No cataloged versions.