Post

Dapr Dashboard Configurations Unauthorized Access Vulnerability Cve 2022 38817

Dapr Dashboard Configurations Unauthorized Access Vulnerability Cve 2022 38817

Dapr Dashboard configurations Unauthorized access vulnerability CVE-2022-38817

Vulnerability Description

Dapr Dashboard has an unauthorized access vulnerability. Unauthorized access can obtain plaintext configuration information for applications such as redis, mongodb, rabbitmq, etc. on the cloud, and can further use these configuration information to obtain sensitive data on the cloud.

Vulnerability Impact

Dapr Dashboard

Network surveying and mapping

“Dapr Dashboard”

Vulnerability reappears

Main page

img

Verify POC

1
/configurations

imgimg

This post is licensed under CC BY 4.0 by the author.