Описание
Due to insufficient input validation of Kyma, authenticated users can pass a Header of their choice and escalate privileges which can completely compromise the cluster.
Ссылки
- Third Party Advisory
- Not Applicable
- Third Party Advisory
- Not Applicable
Уязвимые конфигурации
Конфигурация 1Версия до 1.24.7 (исключая)
cpe:2.3:a:kyma-project:kyma:*:*:*:*:*:*:*:*
EPSS
Процентиль: 66%
0.00517
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-20
EPSS
Процентиль: 66%
0.00517
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-20