Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-43hh-68v6-mf36

Опубликовано: 20 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.4

Описание

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.

EPSS

Процентиль: 53%
0.00798
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.4
redhat
около 1 месяца назад

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.

CVSS3: 9.4
nvd
29 дней назад

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.

EPSS

Процентиль: 53%
0.00798
Низкий

9.4 Critical

CVSS3

Дефекты

CWE-306