Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Improper header sanitization in bored-agent causes escalation of privilege
Vulnerability Description
Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigned user name and groups.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
访问控制不恰当
Vulnerability Title
BoreD Agent 安全漏洞
Vulnerability Description
BoreD Agent是美国Lens团队的一个 BoreD 隧道守护程序的开源代理。 BoreD Agent v0.6.1之前版本存在安全漏洞,该漏洞源于无法清除传入的kubernetes模拟头,攻击者可利用该漏洞覆盖分配的用户名和组。
CVSS Information
N/A
Vulnerability Type
N/A