漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
Vulnerability Description
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.1.6 and 1.2.3, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize component:exec and wirelogs:view using the caller-supplied project query parameter instead of comp.Spec.Owner.ProjectName, allowing a user with a project-scoped grant to execute commands in and read wirelogs from components owned by other projects in the same namespace. This vulnerability is fixed in 1.1.6 and 1.2.3.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
OpenChoreo 授权问题漏洞
Vulnerability Description
OpenChoreo是openchoreo组织开源的一个面向 Kubernetes 的开发者平台。 OpenChoreo 1.2.0-rc.1至1.2.0之前版本存在授权问题漏洞,该漏洞源于internal/openchoreo-api/api/handlers/exec.go和wirelogs.go在授权时使用调用者提供的project查询参数而非comp.Spec.Owner.ProjectName,可能导致具有项目范围授权的用户在同一命名空间中执行命令并读取其他项目组件的wirelogs。
CVSS Information
N/A
Vulnerability Type
N/A