You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Due to insufficient input validation of Kyma, authenticated user can pass a Header of their choice and escalate privileges which can completely compromise the cluster.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Learn more on MITRE.
The product does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used by web browser components that can process raw headers, such as Flash.
Learn more on MITRE.
Problem Type
Header Manipulation
Impact
Due to insufficient input validation of Kyma, authenticated user can pass a Header of their choice and escalate privileges which can completely compromise the cluster.
Patches
The problem was patched in 1.24.7.