漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Camel K: Camel K Cross-Namespace Build Deputy Attack
Vulnerability Description
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can create a Build resource, controlling the Pod generation in a namespace of their choice, including the operator namespace. This issue affects Apache Camel K: from 2.0.0 before 2.8.1, from 2.9.0 before 2.9.2, from 2.10.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1 (or 2.8.1 or 2.9.2), which fixes the issue.
CVSS Information
N/A
Vulnerability Type
资源在另一范围的外部可控制索引
Vulnerability Title
Apache Camel K 安全漏洞
Vulnerability Description
Apache Camel K是美国阿帕奇(Apache)基金会的一个面向Kubernetes与云原生环境的集成运行平台。 Apache Camel K 2.0.0至2.8.1之前版本、2.9.0至2.9.2之前版本和2.10.0至2.10.1之前版本存在安全漏洞,该漏洞源于外部控制资源引用和授权绕过问题,可能导致Kubernetes命名空间中授权用户创建Build资源,控制其选择的命名空间中的Pod生成,包括操作员命名空间。
CVSS Information
N/A
Vulnerability Type
N/A