Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, refactoring coco's SSH/SFTP service and Web Terminal service. Prior to version 2.28.8, using illegal tokens to connect to a Kubernetes cluster through Koko can result in the execution of dangerous commands that may disrupt the Koko container environment and affect normal usage. The vulnerability has been fixed in v2.28.8.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-03-16T16:18:49.977Z
Updated: 2024-08-02T12:30:24.220Z
Reserved: 2023-03-10T18:34:29.227Z
Link: CVE-2023-28110
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-03-16T17:15:09.850
Modified: 2024-11-21T07:54:25.523
Link: CVE-2023-28110
Redhat
No data.