CVE-2022-45933

KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."
References
Link Resource
https://github.com/benc-uk/kubeview/issues/95 Exploit Issue Tracking Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:kubeview_project:kubeview:*:*:*:*:*:*:*:*

Information

Published : 2022-11-26 19:15

Updated : 2022-12-01 10:41


NVD link : CVE-2022-45933

Mitre link : CVE-2022-45933


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

kubeview_project

  • kubeview