CyberRota Analysis
AI-GeneratedKubeEdge CloudCore versions up to 1.23.1 are vulnerable due to a lack of authentication verification for node task status reports received on its HTTPS server, allowing attackers to manipulate upgrade job statuses. This could lead to unauthorized control over the upgrade process, potentially disrupting operations and blocking further upgrades. Organizations using KubeEdge should prioritize this vulnerability to safeguard their cloud infrastructure from potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about node upgrade status and blocking further upgrade scheduling.