CVE-2019-12494: High severity gardener vulnerability
In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET requests from one's own shoot clusters to foreign shoot clusters. This occurs because traffic from shoot to seed via the VPN endpoint is not blocked.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12494?
CVE-2019-12494 is classified as a medium severity vulnerability due to incorrect access control enabling information disclosure.
How do I fix CVE-2019-12494?
To fix CVE-2019-12494, upgrade Gardener to version 0.20.0 or later to ensure proper access controls.
What is affected by CVE-2019-12494?
CVE-2019-12494 affects Gardener versions prior to 0.20.0, significantly impacting seed clusters.
Can CVE-2019-12494 lead to data leakage?
Yes, CVE-2019-12494 can lead to data leakage by allowing unauthorized access to sensitive information across shoot clusters.
Is CVE-2019-12494 a network-related vulnerability?
Yes, CVE-2019-12494 is network-related as it involves improper traffic control between shoot and seed clusters via a VPN endpoint.