漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
Vulnerability Description
Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
使用多个具有重复标识的资源
Vulnerability Title
Traefik 处理逻辑错误漏洞
Vulnerability Description
Traefik是Traefik公司开源的一款负载均衡器。 Traefik 3.0.0版本至3.6.25之前版本和3.7.0版本至3.7.10之前版本存在处理逻辑错误漏洞,该漏洞源于pkg/provider/kubernetes/gateway/目录下的httproute.go、grpcroute.go、tcproute.go和tlsroute.go文件中,Kubernetes Gateway API provider在构建HTTPRoute、GRPCRoute、TCPRoute和TLSRoute路由及服务
CVSS Information
N/A
Vulnerability Type
N/A