KubeEdge是KubeEdge开源的一个 Kubernetes 原生边缘计算框架。基于 Kubernetes 构建,并将本机容器化应用编排和设备管理扩展到边缘主机。 KubeEdge 1.11.1之前版本、1.10.2之前版本 和 1.9.4之前版本存在资源管理错误漏洞,该漏洞源于如果攻击者可以向 CloudHub 发送精心设计的 HTTP 请求,并且该请求具有非常大的主体,则该请求可能通过内存耗尽向量使 HTTP 服务崩溃,攻击者利用该漏洞可以发送大消息来耗尽内存并导致 DoS。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-31073 | 6.5 MEDIUM | KubeEdge Edge ServiceBus module DoS |
| CVE-2022-31074 | 4.5 MEDIUM | KubeEdge Cloud AdmissionController component DoS |
| CVE-2022-31078 | 4.4 MEDIUM | KubeEdge CloudCore Router memory exhaustion |
| CVE-2022-31079 | 4.4 MEDIUM | KubeEdge Cloud Stream and Edge Stream DoS from large stream message |
| CVE-2022-31080 | 4.4 MEDIUM | KubeEdge Websocket Client in package Viaduct: DoS from large response message |
No comments yet