KubeEdge是KubeEdge开源的一个 Kubernetes 原生边缘计算框架。基于 Kubernetes 构建,并将本机容器化应用编排和设备管理扩展到边缘主机。 KubeEdge 1.11.1之前版本、1.10.2之前版本 和 1.9.4之前版本存在资源管理错误漏洞,该漏洞源于如果向其发送包含非常大 Body 的 HTTP 请求,Cloud AdmissionController 中的多个端点可能会受到 DoS 攻击,攻击者利用该漏洞可以发送大消息来耗尽内存并导致 DoS。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-31073 | 6.5 MEDIUM | KubeEdge Edge ServiceBus module DoS |
| CVE-2022-31075 | 4.9 MEDIUM | KubeEdge DoS when signing the CSR from EdgeCore |
| CVE-2022-31078 | 4.4 MEDIUM | KubeEdge CloudCore Router memory exhaustion |
| CVE-2022-31079 | 4.4 MEDIUM | KubeEdge Cloud Stream and Edge Stream DoS from large stream message |
| CVE-2022-31080 | 4.4 MEDIUM | KubeEdge Websocket Client in package Viaduct: DoS from large response message |
No comments yet