漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Tilt: Missing authentication on the network-exposed Tilt HUD server
Vulnerability Description
Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux router with no authenticating middleware. When the HUD is bound to a non-loopback address, an unauthenticated network caller can trigger developer-defined resources, tamper with Tiltfile arguments, read full engine state including the session token, and invoke apiserver resources through the token-attaching /proxy handler. This issue is fixed in version 0.37.4.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Tilt Dev Tilt 授权问题漏洞
Vulnerability Description
Tilt Dev Tilt是Tilt Dev团队的一款持续集成与交付的微服务开发工具。 Tilt Dev Tilt 0.20.8版本至0.37.3版本存在授权问题漏洞,该漏洞源于Tilt HUD HTTP服务器在gorilla/mux路由器上注册处理程序时未使用身份验证中间件,可能导致未经身份验证的网络调用者在HUD绑定到非回环地址时触发开发者定义的资源、篡改Tiltfile参数、读取包括会话令牌在内的完整引擎状态,并通过token-attaching的/proxy处理程序调用apiserver资源。
CVSS Information
N/A
Vulnerability Type
N/A