Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-46254

Опубликовано: 06 нояб. 2023
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used by capsule-proxy gives ServiceAccount tenant owners the right to list Namespaces of other tenants backed by the same owner kind and name. For example consider two tenants solar and wind. Tenant solar, owned by a ServiceAccount named tenant-owner in the Namespace solar. Tenant wind, owned by a ServiceAccount named tenant-owner in the Namespace wind. The Tenant owner solar would be able to list the namespaces of the Tenant wind and vice-versa, although this is not correct. The bug introduces an exfiltration vulnerability since allows the listing of Namespace resources of other Tenants, although just in some specific conditions: 1. capsule-proxy runs with the --disable-caching=false (default value: false) and 2. Tenant owners are ServiceAccount, with the same resource name, but in different Namespaces. This vulnerability doesn't allow any pri

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:clastix:capsule:*:*:*:*:*:*:*:*
Версия до 0.4.5 (исключая)
cpe:2.3:a:clastix:capsule-proxy:*:*:*:*:*:*:*:*
Версия до 0.4.5 (исключая)

EPSS

Процентиль: 46%
0.00233
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.3
github
около 2 лет назад

capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name

EPSS

Процентиль: 46%
0.00233
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo