Grafana Alloy 中的 组件允许能够在被监控命名空间中创建或修改 ServiceMonitor 资源的用户,通过 参数指定任意本地文件。Alloy 会读取该文件,并将其内容作为 Bearer Token 发送到由攻击者控制的抓取端点。这可能泄露 Alloy 进程可访问的文件,包括其投影的 Kubernetes 服务账户(service account)令牌,从而使攻击者获得与 Alloy 相同或更高的 Kubernetes 权限。利用此漏洞需要用户具备 ServiceMonitor 的写权限,且其权限低于
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet