KubeEdge是KubeEdge开源的一个 Kubernetes 原生边缘计算框架。基于 Kubernetes 构建,并将本机容器化应用编排和设备管理扩展到边缘主机。 KubeEdge 1.11.1之前版本、1.10.2之前版本 和 1.9.4之前版本存在安全漏洞,该漏洞源于Cloud Stream 服务器和 Edge Stream 服务器将整条消息读入内存,而不限制此消息的大小,攻击者利用该漏洞可以发送大消息来耗尽内存并导致 DoS。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-31073 | 6.5 MEDIUM | KubeEdge Edge ServiceBus module DoS |
| CVE-2022-31075 | 4.9 MEDIUM | KubeEdge DoS when signing the CSR from EdgeCore |
| CVE-2022-31074 | 4.5 MEDIUM | KubeEdge Cloud AdmissionController component DoS |
| CVE-2022-31078 | 4.4 MEDIUM | KubeEdge CloudCore Router memory exhaustion |
| CVE-2022-31080 | 4.4 MEDIUM | KubeEdge Websocket Client in package Viaduct: DoS from large response message |
No comments yet