threat
engine
.sh
Back
·
··:··
Home
/
Product
/
linuxfoundation spinnaker
Product
linuxfoundation spinnaker
9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-32613
< 2025.3.2
Spinnaker is an open source, multi-cloud continuous delivery platform. Echo like some other services, uses SPeL (Spring Expression
9.9
CRITICAL
CVE-2026-32604
< 2025.3.2
Spinnaker is an open source, multi-cloud continuous delivery platform. In versions prior to 2026.1.0, 2026.0.1, 2025.4.2, and 2025
9.9
CRITICAL
CVE-2025-61916
< 2025.1.6
Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vuln
7.9
HIGH
CVE-2023-39348
< 1.28.8
Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to
4.0
MEDIUM
CVE-2022-23506
< 1.27.3
Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco micros
4.3
MEDIUM
CVE-2021-43832
< 1.25.8
Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipeline creati
10.0
CRITICAL
CVE-2021-39143
< 1.24.7
Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in uses of TA
6.6
MEDIUM
CVE-2020-9301
< 1.21.5
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4,
8.8
HIGH
CVE-2020-9298
< 8.7.0
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to s
7.5
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin