In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET requests from one's own shoot clusters to foreign shoot clusters. This occurs because traffic from shoot to seed via the VPN endpoint is not blocked.
References
| Link | Resource |
|---|---|
| https://groups.google.com/forum/#!topic/gardener/pH6dNIEhv-A | Mailing List Third Party Advisory |
| https://github.com/gardener/vpn/issues/40 | Third Party Advisory |
| https://github.com/gardener/gardener/pull/874 | Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2019-06-05 12:29
Updated : 2020-08-24 10:37
NVD link : CVE-2019-12494
Mitre link : CVE-2019-12494
JSON object : View
CWE
Products Affected
gardener
- gardener


