Sealos is a cloud-native containerization and Kubernetes distribution platform with a tightly scoped product footprint centered on its core platform. The observed vulnerability pattern reflects authorization and access-control weaknesses, a structural concern for infrastructure that manages multi-tenant cluster provisioning and resource isolation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sealos over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-33190CRITICAL Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior to 4.2.1-rc4 an improper configuration of role based access | Jun 29, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-36815HIGH Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sealos billing system, which allow | Jul 3, 2023 | 8.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sealos.
Media articles that mention a CVE ID that affects a product developed by Sealos — matched by CVE ID, not by vendor name.