Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

K8S SSL/TLS漏洞(CVE-2016-2183) #1401

Open
YogurtOlderMan opened this issue Aug 23, 2024 · 3 comments
Open

K8S SSL/TLS漏洞(CVE-2016-2183) #1401

YogurtOlderMan opened this issue Aug 23, 2024 · 3 comments

Comments

@YogurtOlderMan
Copy link

What happened? 发生了什么问题?

目前网安的同事,在针对k8s进行扫描时,触发SSL/TLS漏洞(CVE-2016-2183),

网上搜到的链接:https://blog.csdn.net/zpf17671624050/article/details/129145754

猜测是不是因为内部证书使用了 IDEA、DES 和 3DES 等算法问题

What did you expect to happen? 期望的结果是什么?

解决该漏洞

How can we reproduce it (as minimally and precisely as possible)? 尽可能最小化、精确地描述如何复现问题

此问题,属于漏洞,无法复现

Anything else we need to know? 其他需要说明的情况

No response

Kubernetes version k8s 版本

V1.21.0

Kubeasz version

3.1.0

OS version 操作系统版本

# On Linux:
$ cat /etc/os-release
# paste output here
$ uname -a
# paste output here
CentOS 7.9

Related plugins (CNI, CSI, ...) and versions (if applicable) 其他网络插件等需要说明的情况

@leeonfu
Copy link

leeonfu commented Aug 29, 2024

Could please provide more details logs for our debug?

@YogurtOlderMan
Copy link
Author

Could please provide more details logs for our debug?

QQ20240910-145519

@leeonfu
Copy link

leeonfu commented Sep 10, 2024

@gjmzj Does the project still need maintenance and updates? it's been 4 years since my last PR and there hasn't been any activity since then.
It seems like the project is dead~~ ^-^

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants