Default kuma-cp config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. CorsAllowedDomains: [".*"] reflects any Origin, and LocalhostIsAdmin: true promotes requests from 127.0.0.1 to mesh-system:admin. A cross-origin fetch() from a malicious page returns the admin JWT and signing material.
Am I affected?
You are affected if all of these hold:
kuma-cp runs with default config (CorsAllowedDomains: [".*"] and LocalhostIsAdmin: true).
The control plane is reachable from a browser on the same machine:
kuma-cp run on a developer laptop
Docker --network host or port-publish on a workstation
kubectl port-forward from a machine that also browses the web
The operator visits a page running attacker JavaScript while the control plane is reachable.
You are not affected if:
The control plane runs on a Kubernetes cluster accessed via ClusterIP, NodePort, or LoadBalancer from a remote client.
The control plane runs on an SSH-administered VM with no browser on the host.
CorsAllowedDomains default changed from [".*"] to [] — CORS is now opt-in; set the env var explicitly if you need GUI access.
LocalhostIsAdmin hardened: now requires direct loopback RemoteAddr and Host, and rejects requests carrying proxy-hop headers (X-Forwarded-For), cross-site fetch metadata (Sec-Fetch-Site), or a non-localhost Origin.