In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET requests from one's own shoot clusters to foreign shoot clusters. This occurs because traffic from shoot to seed via the VPN endpoint is not blocked.
References
Link | Resource |
---|---|
https://github.com/gardener/gardener/pull/874 | Issue Tracking Third Party Advisory |
https://github.com/gardener/vpn/issues/40 | Third Party Advisory |
https://groups.google.com/forum/#%21topic/gardener/pH6dNIEhv-A | |
https://github.com/gardener/gardener/pull/874 | Issue Tracking Third Party Advisory |
https://github.com/gardener/vpn/issues/40 | Third Party Advisory |
https://groups.google.com/forum/#%21topic/gardener/pH6dNIEhv-A |
Configurations
History
21 Nov 2024, 04:22
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/gardener/gardener/pull/874 - Issue Tracking, Third Party Advisory | |
References | () https://github.com/gardener/vpn/issues/40 - Third Party Advisory | |
References | () https://groups.google.com/forum/#%21topic/gardener/pH6dNIEhv-A - | |
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 8.5 |
Information
Published : 2019-06-05 19:29
Updated : 2024-11-21 04:22
NVD link : CVE-2019-12494
Mitre link : CVE-2019-12494
CVE.ORG link : CVE-2019-12494
JSON object : View
Products Affected
gardener
- gardener
CWE