MKP 是 Kubernetes 的模型上下文协议(Model Context Protocol, MCP)服务器。在 0.4.1 版本之前, 暴露了默认的 HTTP 端点,而 注册了一个未认证的 工具,该工具接受攻击者可控的 和 参数用于 Pod 日志子资源。 中的 将这些值解析为无界(unbounded)的 参数,而 则通过 将返回的 Kubernetes 日志流复制到内存中的 ,但缺乏应用层面的大小限制。 能够访问默认端口 8080 的 MCP 端点的远程攻击者,可以选择一个累积日志量较大的 Pod,并发送单
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| StacklokLabs | mkp | < 0.4.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| StacklokLabs | mkp | < 0.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet