漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
vCluster Platform: Stored XSS can lead to privilege escalation
Vulnerability Description
vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name field of a templateRef. This can lead to the execution of arbitrary external scripts within the platform's browser context. In the worst case, a malicious user could potentially create a new Global-Admin user, bypassing other security restrictions. The attacker needs the ability to create namespaces. This vulnerability is fixed in 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
vCluster Platform 跨站脚本漏洞
Vulnerability Description
vCluster Platform是vCluster开源的一个虚拟集群管理器。 vCluster Platform 4.4.3之前版本、4.5.5之前版本、4.6.2之前版本、4.7.1之前版本和4.8.0之前版本存在跨站脚本漏洞,该漏洞源于templateRef的name字段存在存储型跨站脚本,可能导致在平台浏览器环境中执行任意外部脚本,恶意用户可能创建新的全局管理员用户绕过其他安全限制。
CVSS Information
N/A
Vulnerability Type
N/A