kuma-dp connects to control plane without verifying TLS certificate when no CA is configured
Description
When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled. The dataplane authentication token is sent over this unverified connection
Impact
An on-path attacker can intercept the dataplane authentication token and impersonate the control plane to the data plane, allowing them to inject a forged bootstrap configuration and take over the proxy
Affected configurations
- Universal mode
kuma-dpstarted against an HTTPS control plane without--ca-cert-file(orKUMA_CONTROL_PLANE_CA_CERTunset)
Not affected
- Kubernetes installs done through the standard installers (
kumactl install control-planeor the official Helm chart). In both cases the control plane's mutating admission webhook injectsKUMA_CONTROL_PLANE_CA_CERTinto every sidecar at pod admission, so eachkuma-dpstarts with the CA already configured
Workarounds
Set --ca-cert-file (or KUMA_CONTROL_PLANE_CA_CERT) on every Universal mode data plane and point it at the control plane's serving CA. Alternatively, terminate the control plane behind a publicly trusted certificate; the patched releases will verify successfully against the operating system trust store with no further configuration
Resources
- Fix: https://github.com/kumahq/kuma/pull/16777
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/kumahq/kuma/v2Go | < 2.7.26 | 2.7.26 |
github.com/kumahq/kuma/v2Go | >= 2.8.0, < 2.9.16 | 2.9.16 |
github.com/kumahq/kuma/v2Go | >= 2.10.0, < 2.11.14 | 2.11.14 |
github.com/kumahq/kuma/v2Go | >= 2.12.0, < 2.12.11 | 2.12.11 |
github.com/kumahq/kuma/v2Go | >= 2.13.0, < 2.13.7 | 2.13.7 |
github.com/kumahq/kumaGo | <= 1.8.1 | — |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.