CWE-322: SSH host key verification disabled — 4 instances of InsecureIgnoreHostKey, K3S_TOKEN exposed
Aperta
- Lingua principale
- Go
- Stelle
- 7.4k
- Fork
- 430
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
### Summary
4 separate locations hardcode `ssh.InsecureIgnoreHostKey()`. K3S_NODE_TOKEN and k3s installer scripts transmitted over unverified SSH. Full K3s cluster bootstrap process can be MITM hijacked.
### Impact
K3s cluster bootstrap credentials exposed. Attacker can compromise entire K3s deployment during setup.
### Remediation
Implement proper host key verification with known_hosts. Full report available.
Guida per i contributori
Nessuna guida per i contributori indicizzata per questo repository
Valutazione
Questa issue non è ancora stata valutata.