Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2gg8-85m5-8r2p

Опубликовано: 15 сент. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Chaos Mesh's Chaos Controller Manager is Missing Authentication for Critical Function

The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service.

Пакеты

Наименование

github.com/chaos-mesh/chaos-mesh

go
Затронутые версииВерсия исправления

< 2.7.3

2.7.3

EPSS

Процентиль: 55%
0.00326
Низкий

7.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
5 месяцев назад

The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service.

EPSS

Процентиль: 55%
0.00326
Низкий

7.5 High

CVSS3

Дефекты

CWE-306