Velero 是一款用于备份、还原和迁移 Kubernetes 集群资源及持久卷的开源工具。在 1.18.1 版本之前,如果攻击者破坏了备份对象存储后端,他们可以上传一个包含父目录路径的恶意备份 tarball(归档文件)。在还原过程中,这些路径可能会跳出预期的解压目录,从而覆盖 Velero Pod 文件系统中的敏感文件。该问题已在 1.18.1 版本中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet