Логотип exploitDog
bind:CVE-2026-23742
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-23742

Количество 2

Количество 2

nvd логотип

CVE-2026-23742

3 дня назад

Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline , for example through a Kubernetes Ingress resource. The configuration inline allows these user to create a script that is able to read the filesystem accessible to the skipper process and if the user has access to read the logs, they an read skipper secrets. This vulnerability is fixed in 0.23.0.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-cc8m-98fm-rc9g

3 дня назад

Skipper is vulnerable to arbitrary code execution through lua filters

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-23742

Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline , for example through a Kubernetes Ingress resource. The configuration inline allows these user to create a script that is able to read the filesystem accessible to the skipper process and if the user has access to read the logs, they an read skipper secrets. This vulnerability is fixed in 0.23.0.

CVSS3: 8.8
0%
Низкий
3 дня назад
github логотип
GHSA-cc8m-98fm-rc9g

Skipper is vulnerable to arbitrary code execution through lua filters

CVSS3: 8.8
0%
Низкий
3 дня назад

Уязвимостей на страницу