漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Migration-planner: agent api ignores jwt source_id claim
Vulnerability Description
A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and UpdateAgentStatus handlers fail to validate the source_id claim within these tokens against the requested source ID. This oversight allows an authenticated attacker with a valid agent token to manipulate data across different tenants, leading to a complete collapse of tenant isolation. This could result in unauthorized overwriting of victim inventory, planting of malicious credential URLs, or corruption of migration assessments.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Migration assessment 安全漏洞
Vulnerability Description
Migration assessment是KubeV2V开源的一个VMware环境评估与迁移建议工具。 Migration assessment存在安全漏洞,该漏洞源于agent-API中间件在处理JWT令牌时,UpdateSourceInventory和UpdateAgentStatus处理程序未能验证令牌中的source_id声明与请求的源ID是否一致,可能导致经过身份验证的攻击者使用有效代理令牌跨租户操作数据,导致租户隔离完全失效,可能导致未经授权覆盖受害者库存、植入恶意凭据URL或破坏迁移评估。
CVSS Information
N/A
Vulnerability Type
N/A