在多云集群引擎(Multicluster Engine, MCE)的 clusterclaims-controller 组件中发现了一个安全漏洞。拥有标准权限以创建和删除 ClusterClaim 资源的租户可通过操纵 字段利用此漏洞。由于缺乏所有权检查机制,该租户能够指定并删除任意 ManagedCluster,包括集群管理端(hub)的 local-cluster 以及其他租户的集群。此漏洞可导致拒绝服务(DoS)攻击,因为它允许未经授权的 ManagedCluster 删除操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Multicluster Engine for Kubernetes | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Multicluster Engine for Kubernetes | - |
cpe:/a:redhat:multicluster_engine
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet