OSV 1.4.0 · unreviewed · 修改于 2026-09-03 23:32
发布时间
2026-08-21 05:31
GitHub 审查时间
—
NVD 发布时间
2026-08-21 03:16
源文件
advisories/unreviewed/2026/08/GHSA-264j-8377-4hmm/GHSA-264j-8377-4hmm.json
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and ServiceImports into any namespace on peer clusters, including critical system namespaces like kube-system and openshift-*. This could lead to privilege escalation or other forms of system compromise within the cluster.
该公告没有提供结构化的受影响软件包信息。