漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Redhatinsights/incluster-checks: incluster-checks: privileged host-chroot debug pods created in shared default namespace enable privilege escalation to node root
Vulnerability Description
A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged debug pods with host filesystem access in the shared default namespace, where any user with the standard edit role can exec into them and obtain root access on cluster nodes.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
带着不必要的权限执行
Vulnerability Title
RedHatInsights In-Cluster Checks 权限许可和访问控制问题漏洞
Vulnerability Description
RedHatInsights In-Cluster Checks是RedHatInsights公司开源的一款集群内检查工具。 RedHatInsights In-Cluster Checks存在权限许可和访问控制问题漏洞,该漏洞源于incluster-checks工具权限管理问题,可能导致具有标准编辑角色的用户在共享默认命名空间中执行特权调试Pod,从而获得集群节点的root访问权限,导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A