Описание
cortex establishes TLS connections with InsecureSkipVerify set to true
A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function.
Пакеты
Наименование
github.com/cortexproject/cortex
go
Затронутые версииВерсия исправления
<= 0.42.1
Отсутствует
Связанные уязвимости
CVSS3: 7.5
nvd
больше 1 года назад
A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function.