In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET requests from one's own shoot clusters to foreign shoot clusters. This occurs because traffic from shoot to seed via the VPN endpoint is not blocked.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-06-05T18:44:33

Updated: 2024-08-04T23:24:38.439Z

Reserved: 2019-05-31T00:00:00

Link: CVE-2019-12494

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-06-05T19:29:00.233

Modified: 2024-11-21T04:22:58.013

Link: CVE-2019-12494

cve-icon Redhat

No data.