Kuma 是一个基于 Envoy 构建的现代服务网格,支持在 Kubernetes 和虚拟机环境中的各类云平台上运行。在 2.7.26、2.9.16、2.11.14、2.12.11 和 2.13.7 之前的版本中,如果用户手动配置了一个指向 HTTPS 控制平面的 kumactl profile,但未指定 --ca-cert-file 参数,则会禁用 TLS 对等方验证,并导致 API 令牌在未经验证的安全连接上传输。网络路径上的攻击者可以拦截用户或管理员的 API 令牌,并以被泄露令牌的用户身份向控制平面发起请求
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet