Search Results (4 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-59361 1 Chaos-mesh 2 Chaos-mesh, Chaos Mesh 2025-10-14 9.8 Critical
The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
CVE-2025-59360 1 Chaos-mesh 2 Chaos-mesh, Chaos Mesh 2025-10-14 9.8 Critical
The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
CVE-2025-59359 1 Chaos-mesh 2 Chaos-mesh, Chaos Mesh 2025-10-14 9.8 Critical
The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code execution across the cluster.
CVE-2025-59358 1 Chaos-mesh 2 Chaos-mesh, Chaos Mesh 2025-10-14 7.5 High
The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service.