Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-847j-gj2f-78j9

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.3
CVSS3: 7.7

Описание

KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoint that accepts unvalidated caller-supplied URLs without allowlist restrictions. Authenticated attackers can supply arbitrary URLs to reach internal services and exfiltrate basic-auth credentials from Secrets in any namespace by leveraging the endpoint's error response handling.

KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoint that accepts unvalidated caller-supplied URLs without allowlist restrictions. Authenticated attackers can supply arbitrary URLs to reach internal services and exfiltrate basic-auth credentials from Secrets in any namespace by leveraging the endpoint's error response handling.

EPSS

Процентиль: 19%
0.00269
Низкий

8.3 High

CVSS4

7.7 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.7
nvd
4 дня назад

KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoint that accepts unvalidated caller-supplied URLs without allowlist restrictions. Authenticated attackers can supply arbitrary URLs to reach internal services and exfiltrate basic-auth credentials from Secrets in any namespace by leveraging the endpoint's error response handling.

EPSS

Процентиль: 19%
0.00269
Низкий

8.3 High

CVSS4

7.7 High

CVSS3

Дефекты

CWE-918