Contour 是一个基于 Envoy 代理的 Kubernetes Ingress 控制器。在版本 1.23.0 至 1.33.4 中,当 配置中同时存在 和 的不兼容组合时,Contour 不会拒绝该配置。因此,来自未发送 TLS SNI 或发送了未识别 SNI(即不匹配任何 FQDN 的 SNI)的客户端的请求,将绕过配置的 JWT 验证,并以无效令牌直接代理转发至上游服务。 该问题已在 Contour v1.33.5 中修复。修复后,Contour 将拒绝并将任何同时启用 与 的 资源标记为无效。受影响资源
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| projectcontour | contour | >= 1.23.0, < 1.33.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| projectcontour | contour | >= 1.23.0, < 1.33.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet