Amazon EKS 网络策略代理(Amazon EKS Network Policy Agent)在 v1.4.0 之前对 Pod 标识符唯一性的验证不当,可能导致经过身份验证的远程用户通过构造能产生 Pod 标识符冲突的 Pod 和命名空间名称,绕过其他命名空间中同集群(co-located)Pod 的网络策略(NetworkPolicy)强制执行机制。 为解决此问题,用户应升级到 Amazon EKS Network Policy Agent 1.4.0 或更高版本,以及 Amazon VPC CNI 托管附
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | amazon-vpc-cni-k8s | 1.14.0< 1.22.4 |
affected |
| AWS | aws-network-policy-agent | < 1.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | aws-network-policy-agent | 0 ~ 1.4.0 | - |
|
| AWS | amazon-vpc-cni-k8s | 1.14.0 ~ 1.22.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet