#1598·k8sgpt

k8sgpt 项目中的漏洞

作者: ankitdn创建于 2025年12月23日更新于 2026年8月23日
标签GitHub Actionscriticalvulnerability

在处理 k8sgpt 项目时,我发现 GitHub.com/kedacore/keda/v2 中存在一个漏洞。扫描报告了一个 Arbitrary File Read 漏洞,该漏洞影响了 KEDA 的 TriggerAuthentication 配置,当与 HashiCorp Vault 结合使用时。由于在加载 Service Account Token 时路径验证不足,具有创建或修改 TriggerAuthentication 资源权限的攻击者可能会从节点文件系统中读取任意文件。

内容来源: k8sgpt-ai/k8sgpt