漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Kong Mesh: kuma-dp connects to the control plane without verifying the TLS certificate when no CA is configured
Vulnerability Description
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled, and the dataplane authentication token is sent over that unverified connection.
An on-path actor can intercept the dataplane authentication token and impersonate the control plane to the data plane, injecting a forged bootstrap configuration and taking over the proxy.
CVSS Information
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Vulnerability Type
证书验证不恰当
Vulnerability Title
Kuma 加密问题漏洞
Vulnerability Description
Kuma是Kuma组织开源的一个基于 Envoy 的现代化服务网格,可在任何云平台上运行,支持单区域或多区域部署,并兼容 Kubernetes 和虚拟机。 Kuma 2.7.26之前版本、2.8.0至2.9.16之前版本、2.10.0至2.11.14之前版本、2.12.0至2.12.11之前版本和2.13.0至2.13.7之前版本存在加密问题漏洞,该漏洞源于TLS对端验证被禁用,可能导致中间人攻击者拦截数据平面认证令牌并冒充控制平面,注入伪造的引导配置从而接管代理。
CVSS Information
N/A
Vulnerability Type
N/A