CVE-2019-12494
Summary
| CVE | CVE-2019-12494 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-05 19:29:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET requests from one's own shoot clusters to foreign shoot clusters. This occurs because traffic from shoot to seed via the VPN endpoint is not blocked. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Google Groups | CONFIRM | groups.google.com | Mailing List, Third Party Advisory |
| Google Groups | groups.google.com | ||
| Add firewall rules to vpn-seed pod · Issue #40 · gardener/vpn · GitHub | MISC | github.com | Third Party Advisory |
| Block new incoming connections to seed cluster from vpn tunnel by DockToFuture · Pull Request #874 · gardener/gardener · GitHub | MISC | github.com | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.