Логотип exploitDog
bind:CVE-2025-64323
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-64323

Количество 2

Количество 2

nvd логотип

CVE-2025-64323

3 месяца назад

kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend service information, routing rules, and cluster metadata. This issue is solved in versions 2.0.5 and 2.1.0.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-4766-x535-jw3r

3 месяца назад

kgateway is missing xDS authorization

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-64323

kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack authentication, allowing any client with unrestricted network access to the xDS port to retrieve potentially sensitive configuration data including certificate data, backend service information, routing rules, and cluster metadata. This issue is solved in versions 2.0.5 and 2.1.0.

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-4766-x535-jw3r

kgateway is missing xDS authorization

CVSS3: 5.3
0%
Низкий
3 месяца назад

Уязвимостей на страницу