All 7 CVE vulnerabilities found in spinnaker, with AI-generated Chinese analysis, references, and POCs.
Vendor: spinnaker
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-32613 | Spinnaker vulnerable to RCE via expression parsing due to unrestricted context handling CWE-94 | 10.0 | Critical | 2026-04-20 |
| CVE-2026-32604 | Spinnaker vulnerable to RCE when using gitrepo artifact types due to improper sanitization of user input on branch and paths CWE-20 | 10.0 | Critical | 2026-04-20 |
| CVE-2025-61916 | Spinnaker vulnerable to SSRF due to improper restrictions on http from user input CWE-20 | 7.9 | High | 2026-01-05 |
| CVE-2023-39348 | Improper log output when using GitHub Status Notifications in spinnaker CWE-532 | 4.0 | Medium | 2023-08-28 |
| CVE-2022-23506 | Spinnaker's Rosco microservice vulnerable to improper log masking on AWS Packer builds CWE-532 | 4.3 | Medium | 2023-01-03 |
| CVE-2021-43832 | Improper Access Control in spinnaker CWE-306 | 10.0 | Critical | 2022-01-04 |
| CVE-2021-39143 | Path Traversal in spinnaker CWE-22 | 6.6 | Medium | 2022-01-04 |
All 7 known CVE vulnerabilities affecting spinnaker with full Chinese analysis, references, and POCs where available.