漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Gardener vulnerable to metadata injection for a project secret that can lead to privilege escalation
Vulnerability Description
Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in the `gardenlet` component of Gardener prior to versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0. It could allow a user with administrative privileges for a Gardener project to obtain control over the seed cluster(s) where their shoot clusters are managed. This CVE affects all Gardener installations where gardener/gardener-extension-provider-gcp is in use. Versions 1.116.4, 1.117.5, 1.118.2, and 1.119.0 fix the issue.
CVSS Information
N/A
Vulnerability Type
转义、元或控制序列转义处理不恰当
Vulnerability Title
Gardener 安全漏洞
Vulnerability Description
Gardener是Gardener开源的一款开源的Kubernetes集群管理工具。该产品支持管理、监控和更新Kubernetes集群。 Gardener 1.116.4之前版本、1.117.5之前版本、1.118.2之前版本和1.119.0之前版本存在安全漏洞,该漏洞可能导致具有管理权限的用户控制种子集群。
CVSS Information
N/A
Vulnerability Type
N/A