漏洞信息
提示
尽管我们采用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。
神龙会尽力确保数据准确,但也请结合实际情况进行甄别与判断。
神龙祝您一切顺利!
漏洞标题
Rhcl: authpolicy callbacks result in denial of service in authorino severity
漏洞描述信息
The Authorino service in the Red Hat Connectivity Link is the authorization service for zero trust API security. Authorino allows the users with developer persona to add callbacks to be executed to HTTP endpoints once the authorization process is completed. It was found that an attacker with developer persona access can add a large number of those callbacks to be executed by Authorino and as the authentication policy is enforced by a single instance of the service, this leada to a Denial of Service in Authorino while processing the post-authorization callbacks.
CVSS信息
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
漏洞类别
未加控制的资源消耗(资源穷尽)
漏洞标题
Red Hat Connectivity Link 资源管理错误漏洞
漏洞描述信息
Red Hat Connectivity Link是美国红帽(Red Hat)公司的一个Kubernetes 网络连接管理平台。 Red Hat Connectivity Link存在资源管理错误漏洞,该漏洞源于开发者可添加大量回调导致拒绝服务。
CVSS信息
N/A
漏洞类别
资源管理错误