漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
IBM Turbonomic Prometurbo agent used by IBM Turbonomic Application Resource Management is affected by a single vulnerability
Vulnerability Description
IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
IBM Turbonomic prometurbo agent 安全漏洞
Vulnerability Description
IBM Turbonomic prometurbo agent是美国国际商业机器(IBM)公司的一个监控代理组件。 IBM Turbonomic prometurbo agent 8.16.0版本至8.17.6版本存在安全漏洞,该漏洞源于授予过多集群范围权限,可能导致攻击者泄露敏感凭据并提升权限。
CVSS Information
N/A
Vulnerability Type
N/A