漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent
Vulnerability Description
A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to the target namespace.
An attacker with git push access to a
Fleet-monitored repository could overwrite Pod Security Standards (PSS)
enforcement labels on a target namespace. This allows the attacker to
weaken admission controls and deploy workloads that PSS policies would
otherwise block.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
不充分的凭证保护机制
Vulnerability Title
Rancher Fleet 信任管理问题漏洞
Vulnerability Description
Rancher Fleet是Rancher公司的一款容器集群监控与管理平台。 Rancher Fleet存在信任管理问题漏洞,该漏洞源于agent-side deployer没有过滤namespaceLabels中的安全敏感密钥,可能导致具有git推送权限的攻击者重写Pod Security Standards执行标签,从而削弱准入控制并部署被PSS策略阻止的工作负载。以下版本受到影响:0.15.0版本至0.15.2之前版本、0.14.0版本至0.14.6之前版本、0.13.0版本至0.13.11之前版本
CVSS Information
N/A
Vulnerability Type
N/A