漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when importing data into PVCs from container registries. This could enable man-in-the-middle attacks between a container registry and the virt-cdi-component, leading to possible undetected tampering of trusted container image content.
CVSS Information
N/A
Vulnerability Type
证书验证不恰当
Vulnerability Title
kubevirt containerized data importer 安全漏洞
Vulnerability Description
kubevirt containerized data importer是一款针对Kubernetes的数据导入器。 kubevirt containerized data importer 1.4.0版本至1.5.3版本中存在安全漏洞,该漏洞源于程序关闭了TLS证书验证功能。攻击者可利用该漏洞进行篡改操作。
CVSS Information
N/A
Vulnerability Type
N/A