CPE
high
advisory
Authenticated OS Command Injection in OpenChoreo Workflow Plane
1 TTP 1 CVEAuthenticated users can trigger OS command injection in OpenChoreo workflow templates by supplying crafted parameters that are insecurely interpolated into shell execution scripts.
openchoreo
vulnerability
remote-code-execution
kubernetes
podman
1t
1c
critical
advisory
Unauthenticated API Access in OpenChoreo Cluster-Gateway
2 TTPs 1 CVEOpenChoreo cluster-gateway versions prior to 1.0.2, 1.1.2, and 1.2.0 are vulnerable to unauthenticated access of management APIs on externally exposed listeners, enabling remote execution and cluster-wide compromise.
OpenChoreo cluster-gateway
2t
1c