Description
In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET requests from one's own shoot clusters to foreign shoot clusters. This occurs because traffic from shoot to seed via the VPN endpoint is not blocked.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-4090 | In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET requests from one's own shoot clusters to foreign shoot clusters. This occurs because traffic from shoot to seed via the VPN endpoint is not blocked. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:24:38.439Z
Reserved: 2019-05-31T00:00:00.000Z
Link: CVE-2019-12494
No data.
Status : Modified
Published: 2019-06-05T19:29:00.233
Modified: 2024-11-21T04:22:58.013
Link: CVE-2019-12494
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD