Argo Rollouts 仪表盘(版本至 1.10.0)绑定到所有网络接口,并在没有身份验证、授权或 CSRF 保护的情况下,暴露了具有变更能力的 Rollout 操作。同一网络上的攻击者可以针对操作员 kubeconfig 可访问的所有命名空间,调用 PromoteRollout(提升 Rollout)、AbortRollout(中止 Rollout)、RestartRollout(重启 Rollout)、SetRolloutImage(设置 Rollout 镜像)、UndoRollout(撤销 Rollout
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| argoproj | argo-rollouts | ≤ 1.10.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| argoproj | argo-rollouts | 0 ~ 1.10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet