PT-2026-83452 · Kubeedge · Cloudcore
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
KubeEdge CloudCore versions prior to 1.23.2
Description
The HTTPS server in CloudCore accepts node task status reports without authentication verification. An attacker can access CloudCore on port 10002 to manipulate the status of upgrade jobs, marking them as succeeded or failed. This action deceives the control plane regarding the actual status of node upgrades and prevents the scheduling of subsequent upgrades.
Recommendations
Update KubeEdge CloudCore to version 1.23.2 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudcore