Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
Vulnerability Description
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowing a malicious or compromised issuer to perform blind SSRF, substitute and cache malicious JWKS keys, or disclose ServiceAccount tokens to external hosts. Version 1.8.6 blocks cross-host redirects, restricts token injection, and restricts local token loading. No known workarounds are available.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
sigstore fulcio 服务端请求伪造漏洞
Vulnerability Description
sigstore fulcio是sigstore组织的一个代码签名证书颁发服务。 sigstore fulcio 1.8.5及之前版本存在服务端请求伪造漏洞,该漏洞源于在OIDC发现过程中不正确地跟随跨主机重定向并附加Kubernetes ServiceAccount令牌,可能导致恶意或受入侵的签发者执行盲SSRF、替换和缓存恶意JWKS密钥或向外部主机泄露ServiceAccount令牌。
CVSS Information
N/A
Vulnerability Type
N/A