Kubernetes是美国Linux基金会的一套开源的Docker容器集群管理系统。该系统为容器化的应用提供资源调度、部署运行、服务发现和扩容缩容等功能。 kubernetes 存在安全漏洞,攻击者可利用该漏洞通过创建具有精心编制的子路径卷装载的pod,以访问卷外的文件和目录,包括主机节点的文件系统上的文件和目录
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kubernetes | Kubernetes | unspecified ~ 1.19.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Exploit for CVE-2021-25741 vulnerability | https://github.com/Betep0k/CVE-2021-25741 | POC Details |
| 2 | fork on Betep0k/CVE-2021-25741/fork whose images is useless and test on metarget | https://github.com/cdxiaodong/CVE-2021-25741 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-8561 | 4.1 MEDIUM | Webhook redirect in kube-apiserver |
| CVE-2021-25740 | 3.1 LOW | Holes in EndpointSlice Validation Enable Host Network Hijack |
No comments yet