Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream
Vulnerability Description
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebSocket at /ws/view is gated by a CSRF token, but the token is served by the unauthenticated /api/websocket_token endpoint and the upgrader accepts clients that omit an Origin header. When the HUD is network-exposed, an attacker who can reach the listener can open the HUD WebSocket and receive the full view stream, including session state, Tiltfile contents, resource statuses, and continued updates. This issue is fixed in version 0.37.4.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
对数据真实性的验证不充分
Vulnerability Title
Tilt Dev Tilt 输入验证错误漏洞
Vulnerability Description
Tilt Dev Tilt是Tilt Dev团队的一款持续集成与交付的微服务开发工具。 Tilt Dev Tilt 0.24.0版本至0.37.3版本存在输入验证错误漏洞,该漏洞源于CSRF令牌认证机制缺陷,未经身份验证的端点可分发令牌且WebSocket接受缺少Origin标头的客户端,导致网络暴露环境下攻击者可通过访问监听器打开HUD WebSocket获取完整视图流,包括会话状态、Tiltfile内容、资源状态及持续更新。
CVSS Information
N/A
Vulnerability Type
N/A