Weave develops a focused suite of GitOps automation and infrastructure-management tools, including Weave GitOps and related controller and agent components, that orchestrate application deployment and configuration across cloud environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through weakness classes centered on sensitive-information exposure, OS command injection, and cleartext transmission—reflecting the elevated privileges and secret-handling demands of deployment automation platforms. Defenders should prioritize tracking this vendor's security updates and audit GitOps pipeline configurations for credential exposure and command-injection risks; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weave over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35975CRITICAL The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution in the machine running the exte | Aug 18, 2022 | 9.8 | 29 | NO | NO |
CVE-2020-35464CRITICAL Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may all | Dec 15, 2020 | 9.8 | 29 | NO | NO |
CVE-2022-31098HIGH Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in the logging of Weave | Jun 27, 2022 | 7.5 | 26 | NO | NO |
CVE-2022-23508HIGH Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulnerability in GitOps run could al | Jan 9, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-35976CRITICAL The GitOps Tools Extension for VSCode relies on kubeconfigs in order to communicate with Kubernetes clusters. A specially crafted kubeconfig leads to arbitrary code execution on be | Aug 18, 2022 | 9.8 | 24 | NO | NO |
CVE-2020-26278HIGH Weave Net is open source software which creates a virtual network that connects Docker containers across multiple hosts and enables their automatic discovery. Weave Net before vers | Jan 20, 2021 | 8.0 | 24 | NO | NO |
CVE-2024-25545HIGH An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework component. | Apr 12, 2024 | 7.8 | 22 | NO | NO |
CVE-2022-23509MEDIUM Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. GitOps run has a local S3 bucket which | Jan 9, 2023 | 6.0 | 21 | NO | NO |
CVE-2023-34236MEDIUM Weave GitOps Terraform Controller (aka Weave TF-controller) is a controller for Flux to reconcile Terraform resources in a GitOps way. A vulnerability has been identified in Weave | Jul 14, 2023 | 6.5 | 19 | NO | NO |
CVE-2020-11091MEDIUM In Weave Net before version 2.6.3, an attacker able to run a process as root in a container is able to respond to DNS requests from the host and thereby insert themselves as a fake | Jun 3, 2020 | 5.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weave.
Media articles that mention a CVE ID that affects a product developed by Weave — matched by CVE ID, not by vendor name.