KubeEdge CloudCore 1.23.1 及更早版本在其 HTTPS 服务器上接受节点任务状态报告,但未进行身份验证。攻击者可以通过端口 10002 访问 CloudCore,将升级任务标记为成功或失败,从而误导控制平面对节点升级状态的判断,并阻止后续升级任务的调度。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet