Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows unauthenticated catalog write/delete
Vulnerability Description
OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.providers.guest.dangerouslyAllowOutsideDevelopment to true, exposing /api/* without authentication and allowing unauthenticated catalog reads, scaffolder log reads, and catalog location creation or deletion. This issue is fixed in versions 1.0.4, 1.1.4, and 1.2.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
OpenChoreo Backstage Plugins 授权问题漏洞
Vulnerability Description
OpenChoreo Backstage Plugins是openchoreo组织的一系列扩展软件功能的插件组件。 OpenChoreo Backstage Plugins 1.0.4之前版本、1.1.4之前版本和1.2.1之前版本存在授权问题漏洞,该漏洞源于硬编码禁用默认认证策略,可能导致未经身份验证的攻击者读取目录数据、读取scaffolder日志以及创建或删除目录位置。
CVSS Information
N/A
Vulnerability Type
N/A