maclof kubernetes-client 在 0.17.0 至 0.32.0(不含 0.32.0)版本中,当 kubeconfig 配置文件缺少 certificate-authority-data 字段时,parseKubeconfig() 和 parseKubeconfigFile() 方法会禁用 TLS 证书验证,同时忽略 insecure-skip-tls-verify 设置。这使得中间人攻击者能够伪装成 Kubernetes API 服务器,窃取 Bearer Token 或 Basic 认证凭据
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| maclof | kubernetes-client | 0.17.0 ~ 0.32.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet