在 Eclipse aeriOS 的当前开发版本(尚未正式发布)中,API 网关组件中包含的 KrakenD 实例将 参数硬编码为 ,且无法通过 Helm Chart 配置进行覆盖。该设置会在 KrakenD 获取用于验证 Bearer 令牌的 JSON Web Key Set(JWKS)时禁用 TLS 证书验证,从而可能允许能够拦截此通信的攻击者提供一个恶意的 JWKS,进而破坏令牌验证过程。 该问题已通过将该参数改为可通过 Helm 布尔值 进行配置来修复,并默认将其设置为 ,从而确保 TLS 证书验证默认启用
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse aeriOS | 371ea2101e42aa6503161ce08bbe986e319a9c2f< e680c69c34b82db4944517198330cc447a1e8f98 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse aeriOS | 371ea2101e42aa6503161ce08bbe986e319a9c2f ~ e680c69c34b82db4944517198330cc447a1e8f98 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82958 | 7.6 HIGH | CVE-2026-82958 |
| CVE-2026-84175 | 5.3 MEDIUM | Eclipse Ditto 3.0.0至3.9.6 服务器端请求伪造漏洞 |
No comments yet