KubeSphere是KubeSphere基金会开源的一个云原生管理平台。 KubeSphere 4.0.0版本至4.1.3-rc.0版本存在服务端请求伪造漏洞,该漏洞源于cluster-controller reconciliation(pkg/utils/clusterclient/clusterclient.go,addCluster)在处理Cluster自定义资源的连接配置时,对CRD指定的Kubernetes API端点仅进行URL语法解析,未限制回环地址、私有地址、链路本地地址或云元数据地址,
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kubesphere | KubeSphere | 4.0.0≤ 4.1.3-rc.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kubesphere | KubeSphere | 4.0.0 ~ 4.1.3-rc.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet