MODERATEGo →
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset
Affected packages
- github.com/basekick-labs/arc
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/Basekick-Labs/arc/security/advisories/GHSA-p378-jp5r-gpgw
- https://github.com/Basekick-Labs/arc/pull/505
- https://github.com/Basekick-Labs/arc/commit/38402ad2ebddd32c15bf4a0fc9c22c920e5685df
- https://github.com/Basekick-Labs/arc
- https://github.com/Basekick-Labs/arc/releases/tag/v26.06.2
Structured record: https://osv.dev/vulnerability/GHSA-p378-jp5r-gpgw
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta