In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET requests from one's own shoot clusters to foreign shoot clusters. This occurs because traffic from shoot to seed via the VPN endpoint is not blocked.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2019-06-05T18:44:33
Updated: 2024-08-04T23:24:38.439Z
Reserved: 2019-05-31T00:00:00
Link: CVE-2019-12494

No data.

Status : Modified
Published: 2019-06-05T19:29:00.233
Modified: 2024-11-21T04:22:58.013
Link: CVE-2019-12494

No data.