OSV 1.4.0 · unreviewed · 修改于 2026-09-03 23:32
发布时间
2026-08-21 05:31
GitHub 审查时间
—
NVD 发布时间
2026-08-21 03:16
源文件
advisories/unreviewed/2026/08/GHSA-7fh9-j94v-w42j/GHSA-7fh9-j94v-w42j.json
A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating EndpointSlices with attacker-controlled IP addresses, causing other clusters' lighthouse DNS to redirect legitimate service traffic to malicious endpoints. This enables a remote attacker to conduct transparent Man-in-the-Middle (MITM) attacks on cross-cluster service communications, potentially leading to unauthorized information disclosure and data manipulation.
该公告没有提供结构化的受影响软件包信息。