Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
Vulnerability Description
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to invoke /api/proxy/ and /api/exec/ operations, proxy the data-plane Kubernetes API, and execute commands in workload pods in multi-cluster deployments. This issue is fixed in versions 1.0.2 and 1.1.2.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
OpenChoreo 授权问题漏洞
Vulnerability Description
OpenChoreo是openchoreo组织开源的一个面向 Kubernetes 的开发者平台。 OpenChoreo 1.0.2之前版本和1.1.2之前版本存在安全漏洞,该漏洞源于internal/cluster-gateway/server.go在外部可达的代理监听器上提供面向调用方的管理API且未进行身份验证,可能导致网络可达的攻击者调用/api/proxy/和/api/exec/操作,代理数据平面Kubernetes API,并在多集群部署的工作负载pod中执行命令。
CVSS Information
N/A
Vulnerability Type
N/A