漏洞标题
EdgeXFoundry的配置文件API将消息总线密钥暴露给本地未授权的用户
漏洞描述信息
EdgeXFoundry中的配置API将消息总线凭据暴露给本地未身份验证的用户
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
漏洞类别
N/A
漏洞标题
Configuration API in EdgeXFoundry exposes message bus credentials to local unauthenticated users
漏洞描述信息
EdgeX Foundry is an open source project for building a common open framework for Internet of Things edge computing. Prior to version 2.1.1, the /api/v2/config endpoint exposes message bus credentials to local unauthenticated users. In security-enabled mode, message bus credentials are supposed to be kept in the EdgeX secret store and require authentication to access. This vulnerability bypasses the access controls on message bus credentials when running in security-enabled mode. (No credentials are required when running in security-disabled mode.) As a result, attackers could intercept data or inject fake data into the EdgeX message bus. Users should upgrade to EdgeXFoundry Kamakura release (2.2.0) or to the June 2022 EdgeXFoundry LTS Jakarta release (2.1.1) to receive a patch. More information about which go modules, docker containers, and snaps contain patches is available in the GitHub Security Advisory. There are currently no known workarounds for this issue.
CVSS信息
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
漏洞类别
信息暴露
漏洞标题
EdgeX Foundry 信息泄露漏洞
漏洞描述信息
EdgeX Foundry是一个开源项目,用于构建物联网边缘计算的通用开放框架。 EdgeX Foundry 2.1.1之前版本存在信息泄露漏洞,该漏洞源于/api/v2/config 端点向本地未经身份验证的用户公开消息总线凭据。
CVSS信息
N/A
漏洞类别
信息泄露