漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Kong Mesh multi-zone: the global control plane attributes KDS-synced resources by an unvalidated in-band zone identifier
Vulnerability Description
On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlPlane.Identifier rather than the authenticated zone identity derived from the connection. Authenticated zones can have the global control plane store and re-distribute those resources as belonging to another zone.
The result is a cross-zone isolation bypass: the holder of a single enrolled zone's credential can inject, attribute, and overwrite resources in another zone's namespace mesh-wide.
The root cause lives in Kuma's open-source KDS sync code, which Kong Mesh's control plane is built on.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:N/SC:L/SI:L/SA:N
Vulnerability Type
对数据真实性的验证不充分
Vulnerability Title
Kuma 输入验证错误漏洞
Vulnerability Description
Kuma是Kuma组织开源的一个基于 Envoy 的现代化服务网格,可在任何云平台上运行,支持单区域或多区域部署,并兼容 Kubernetes 和虚拟机。 Kuma 2.7.29之前版本、2.8.0至2.9.19之前版本、2.10.0至2.11.18之前版本、2.12.0至2.12.14之前版本、2.13.0至2.13.10之前版本和2.14.0至2.14.2之前版本存在安全漏洞,该漏洞源于KDS同步过程中使用带内且由发送方控制的ControlPlane.Identifier而非连接认证的区域身份,可能导
CVSS Information
N/A
Vulnerability Type
N/A