Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Critical Red Hat Kubernetes SSRF Flaw Exposes Internal Services Across Managed Clusters

Abinaya
4 hours ago
22 Visninger
0 Kommentarer
Critical Red Hat Kubernetes SSRF Flaw Exposes Internal Services Across Managed Clusters

Red Hat has disclosed CVE-2026-66794, a high-severity Server-Side Request Forgery vulnerability affecting the cluster-proxy-addon component in Multicluster Engine for Kubernetes. The issue carries a CVSS v3.1 score of 9.3. It could allow unauthenticated remote attackers to reach otherwise inaccessible services running across managed Kubernetes clusters. The vulnerability exists in a user-facing route exposed by the cluster proxy add-on. According to Red Hat, the route does not properly enforce authentication and authorization before forwarding requests. An attacker who can access this endpoint can manipulate URL path segments to make the proxy send requests to arbitrary services in managed clusters. This behavior is classified...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!