Vendor
high
advisory
Path Traversal in Uber Kraken
1 rule 1 TTP 1 CVEUber Kraken versions 0.1.29 and earlier contain a path traversal vulnerability in the /tags/{tag} endpoint, allowing unauthenticated attackers to read arbitrary files from the filesystem.
Kraken
path-traversal
vulnerability
webserver
1r
1t
1c
high
advisory
Kraken P2P Cache Poisoning via Insecure Digest Validation
1 TTP 1 CVEKraken agents are vulnerable to cache poisoning because they rely on CRC32 checksums instead of SHA-256 digests to verify peer-to-peer blobs, enabling malicious peers to inject unauthorized container images.
Kraken
1t
1c