The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/chaos-mesh/chaos-mesh(Go) | 0 | 2.7.3 | N/A |
CVSS Metrics