You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Affected endpoint:
GET /config
Details:
While the delivery platform is running, the application periodically sends configuration requests (GET /config) and health checks (GET /clusters/main/healthz). While sending a GET /config request application reveals the KUBERNETES_SERVICE_HOST's internal IP address in the responses, intended for internal use within the cluster and backend systems. This exposure could allow attackers, in the event of a compromised pod, to target the system (for example, with DOS/DDOS attacks) or to learn the internal IP addressing schema.
The text was updated successfully, but these errors were encountered:
Affected endpoint:
GET /config
Details:
While the delivery platform is running, the application periodically sends configuration requests (GET /config) and health checks (GET /clusters/main/healthz). While sending a GET /config request application reveals the KUBERNETES_SERVICE_HOST's internal IP address in the responses, intended for internal use within the cluster and backend systems. This exposure could allow attackers, in the event of a compromised pod, to target the system (for example, with DOS/DDOS attacks) or to learn the internal IP addressing schema.
The text was updated successfully, but these errors were encountered: