以下是对该漏洞描述的中文翻译,力求准确传达技术细节: Harness 3.3.0 及之前版本在基础设施提供方(Infrastructure Provider)的读取接口中缺少访问控制验证,允许已认证用户获取其不属于的空间(Spaces)中的提供方配置。攻击者可以通过在 端点传入任意的空间标识符,从而泄露敏感的提供方元数据,包括 Docker 端点、TLS 证书路径以及云项目标识符。 术语说明(供参考): Infrastructure Provider: 基础设施提供方 Spaces: 工作空间(Harness 中的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet