漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Following the Gardener architecture, the Kubernetes apiserver of a Gardener managed shoot cluster resides in the corresponding seed cluster. Due to missing network isolation a shoot's apiserver can access services/endpoints in the private network of its corresponding seed cluster. Combined with other minor Kubernetes security issues, the missing network isolation theoretically can lead to compromise other shoot or seed clusters in the "Gardener" context. The issue is rated high due to the high impact of a potential exploitation in "Gardener" context. This was fixed in Gardener release 0.12.4.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Gardener 访问控制错误漏洞
Vulnerability Description
Gardener是一跨开源的Kubernetes集群管理工具。该产品支持管理、监控和更新Kubernetes集群。 Gardener中存在安全漏洞,该漏洞源于程序没有进行网络隔离。攻击者可利用该漏洞访问私人网络中的服务/端点。
CVSS Information
N/A
Vulnerability Type
N/A