云虫漏洞库

CVE-2026-32637 - Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-directory paths that escape the extraction directory during restore and overwrite sensitive files in the Velero pod filesystem. This issue is fixed in version 1.18.1. - 漏洞详情

漏洞编号:CVE-2026-32637

风险等级:未知

漏洞来源:CVE

CVE 编号:CVE-2026-32637

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-22

发布/更新时间:2026-08-25 / 2026-08-28

漏洞描述

Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-directory paths that escape the extraction directory during restore and overwrite sensitive files in the Velero pod filesystem. This issue is fixed in version 1.18.1.

相关链接

相关漏洞

« 返回首页