- How many CVEs does spinnaker have?
- spinnaker has 11 published CVE records since 2020, including 6 in the last two years.
- How many spinnaker CVEs are in CISA KEV?
- None of spinnaker's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
- Which spinnaker products have the most CVEs?
- The spinnaker products with the most published CVEs are spinnaker, io.spinnaker.clouddriver:clouddriver-artifacts, io.spinnaker.orca:orca-core, io.spinnaker.clouddriver:clouddriver-artifacts-gitrepo, io.spinnaker.echo:echo-pipelinetriggers.
- What are the most common weakness types in spinnaker CVEs?
- spinnaker's CVEs most often map to these CWE weakness types: CWE-532 (Insertion of Sensitive Information into Log File), CWE-20 (Improper Input Validation), CWE-306 (Missing Authentication for Critical Function), CWE-470 (Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')).
- Are there public exploits for spinnaker vulnerabilities?
- Yes — 1 of spinnaker's CVEs have a known public exploit.
- How many critical spinnaker vulnerabilities are there?
- spinnaker has 4 critical and 6 high-severity CVEs.
- What is the average severity of spinnaker CVEs?
- The average CVSS base score across spinnaker's scored CVEs is 8.3.