Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
Vulnerability Description
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
OpenChoreo 权限许可和访问控制问题漏洞
Vulnerability Description
OpenChoreo是openchoreo组织开源的一个面向 Kubernetes 的开发者平台。 OpenChoreo 1.0.3之前版本、1.1.0至1.1.3之前版本和1.2.0-rc.1至1.2.0-rc.2之前版本存在安全漏洞,该漏洞源于internal/cluster-gateway/server.go中的/api/proxy/、/api/exec/和/api/wirelogs/接口暴露在内部监听器上,且无需客户端证书或令牌,可能导致任意网络可达的调用者读取租户Kubernetes Secre
CVSS Information
N/A
Vulnerability Type
N/A