Skip to main content

Threats Tagged 'cwe-1357'

View all threats tagged with 'cwe-1357'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-1357

Threats Tagged 'cwe-1357'

Click on any threat for detailed analysis and mitigation recommendations

A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials or the publication of malicious images. The workflow also exposes the default GitHub token, increasing the severity of the compromise.

Join the discussion

Dell PowerProtect One versions 20.1.0.0 and below have a vulnerability involving reliance on an insufficiently trustworthy component. This flaw could allow an unauthenticated remote attacker to perform cache poisoning. The vulnerability has a medium severity rating with a CVSS score of 5.3. No official patch or remediation guidance is currently available from the vendor.

Join the discussion

CVE-2026-75569 is a vulnerability in the Red Hat multicluster engine for Kubernetes where the build process of the mce-operator-bundle fetches and executes scripts from a remote repository without integrity verification. This flaw allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build process, potentially compromising the build and leading to distribution of malicious software. The vulnerability has a high severity rating with a CVSS score of 7.7. Red Hat has issued security advisories and updates addressing this issue in later versions of the multicluster engine for Kubernetes.

Join the discussion

A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image.

Join the discussion

NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

Join the discussion

Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published in PyPI. An attacker could claim this namespace and upload arbitrary (malicious) code to the package, and then exploit pip install commands by injecting the malicious dependency in the solve. This issue has been fixed in version 25.3.0. A workaround involves using --no-deps for pip install-ing the project from the repository.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cwe-1357
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses