Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31055

Опубликовано: 13 июн. 2022
Источник: nvd
CVSS3: 7.5
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was broken and allowed traffic from any IP. The problem has been patched in v1.6.0. As a workaround, those who want to test challenges privately can mark them as public: false and use kctf chal debug port-forward to connect.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:google:kctf:*:*:*:*:*:*:*:*
Версия до 1.6.0 (исключая)

EPSS

Процентиль: 44%
0.0021
Низкий

7.5 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-Other

EPSS

Процентиль: 44%
0.0021
Низкий

7.5 High

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-Other