PT-2023-18532 · Unknown · Kubeoperator
CVSS v3.1
7.3
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
KubeOperator versions 3.16.3 and below
Description
The issue allows unauthorized access to API interfaces, potentially leaking sensitive information and allowing takeover of the cluster under certain conditions. This is due to a flaw in handling routing permissions.
Recommendations
For versions 3.16.3 and below, upgrade to version 3.16.4 to resolve the issue. As a temporary workaround, consider restricting access to API interfaces until the upgrade is applied.
Exploit
Correção
DoS
Incorrect Authorization
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kubeoperator