One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 4553469
Date de publication 2022-05-06 02:15:07 (vue: 2022-05-06 06:06:12)
Titre CVE-2022-24878
Texte Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to cause a Denial of Service at the controller level. Workarounds include automated tooling in the user's CI/CD pipeline to validate `kustomization.yaml` files conform with specific policies. This vulnerability is fixed in kustomize-controller v0.24.0 and included in flux2 v0.29.0. Users are recommended to upgrade.
Envoyé Oui
Condensat 2022 24878 `kustomization allows are attacker automated cause ci/cd conform continuous controller cve delivery denial extensible files fixed flux flux2 include included kubernetes kustomize level malicious open path pipeline policies recommended service solution specific tooling traversal upgrade user users validate vulnerability workarounds yaml`
Tags Vulnerability
Stories Uber
Notes ★★★★★
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: