漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running container which mounts /etc/kubernetes or has local access to the node, to copy this kubeconfig file and attempt to add their own node to the OpenShift cluster. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects versions before openshift4/ose-machine-config-operator v4.7.0-202105111858.p0.
CVSS Information
N/A
Vulnerability Type
特权授予不正确
Vulnerability Title
OpenShift 安全漏洞
Vulnerability Description
Red Hat OpenShift是美国红帽(Red Hat)公司的一款平台即服务(PaaS)云计算平台,它支持构建、测试、部署和运行应用程序。 OpenShift存在安全漏洞,该漏洞允许攻击者可利用该漏洞访问一个运行的容器,该容器装载kubernetes或对节点有本地访问权,复制这个kubecconfig文件,并尝试将自己的节点添加到OpenShift集群。
CVSS Information
N/A
Vulnerability Type
N/A