External Secrets Operator 从第三方服务读取信息,并自动将其注入为 Kubernetes Secrets。在版本 0.10.0 至 1.3.2(不含)之间,webhook 生成器初始化顺序存在一个缺陷:在正确设置了标签强制启用标志( )之后,该标志又被错误地清除。这导致系统跳过了对 provider 端 标签的检查,从而使本应因缺少必要标签而失败的操作成功执行。正确的行为应是失败,并提示:“秘密中缺少所需标签 'external-secrets.io/type: webhook'。请更新秘密
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| external-secrets | external-secrets | >= 0.10.0, < 1.3.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| external-secrets | external-secrets | >= 0.10.0, < 1.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet