Логотип exploitDog
bind:CVE-2023-36815
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-36815

Количество 2

Количество 2

nvd логотип

CVE-2023-36815

больше 2 лет назад

Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sealos billing system, which allows users to control the recharge resource account `sealos[.] io/v1/Payment`, resulting in the ability to recharge any amount of 1 renminbi (RMB). The charging interface may expose resource information. The namespace of this custom resource would be user's control and may have permission to correct it. It is not clear whether a fix exists.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-vpxf-q44g-w34w

больше 2 лет назад

Sealos billing system permission control defect

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-36815

Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sealos billing system, which allows users to control the recharge resource account `sealos[.] io/v1/Payment`, resulting in the ability to recharge any amount of 1 renminbi (RMB). The charging interface may expose resource information. The namespace of this custom resource would be user's control and may have permission to correct it. It is not clear whether a fix exists.

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-vpxf-q44g-w34w

Sealos billing system permission control defect

CVSS3: 7.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу