capsule-proxy是允许克服 Kubernetes API Server 在列出拥有的集群范围资源方面的限制,例如 Namespace、Ingress 和 Storage Classes、Nodes 以及 Capsule 涵盖的其他资源。 capsule-proxy 0.2.1之前版本存在安全漏洞,该漏洞源于软件缺少对于Connection头部的校验,具有正确身份验证机制的攻击者可利用该漏洞可能会使用恶意的“Connection”头启动对Kubernetes API服务器的权限升级攻击。该漏洞允许
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| clastix | capsule-proxy | < 0.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet