Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Kubernetes kube-controller-manager SSRF
Vulnerability Description
The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback services).
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Kubernetes 代码问题漏洞
Vulnerability Description
Kubernetes(K8s)是云原生计算基金会(Cloud Native Computing Foundation)的一个开源系统,用于自动部署、扩展和管理容器化应用程序。 Kubernetes中的kube-controller-manager存在代码问题漏洞。攻击者可利用该漏洞从未受保护的端点上获取任意内容(500字节)。以下产品及版本受到影响:kube-controller-manager v1.15.12之前版本,v1.16.9之前版本,v1.17.5之前版本,v1.18.0之前版本。
CVSS Information
N/A
Vulnerability Type
N/A