Chaotic Deputy: Critical vulnerabilities in Chaos Mesh lead to Kubernetes cluster takeover
jfrog.com | 博客 | #cloud | #rce | #kubernetes | #jfrog | #vulnerability-disclosure | #cloud-native | #chaos-mesh | #cve-2025-59358
摘要
JFrog 披露 Chaos Mesh「Chaotic Deputy」四枚 CVE,其中三枚 CVSS 9.8:集群内攻击者(含非特权 Pod)可在任意 Pod 上执行代码;修复于 2.7.3,Azure Chaos Studio 等也受影响。
- 发布时间
- 收录时间
Skip to content