Логотип exploitDog
bind:CVE-2023-48312
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-48312

Количество 2

Количество 2

nvd логотип

CVE-2023-48312

около 2 лет назад

capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalation vulnerability which is based on a missing check if the user is authenticated based on the `TokenReview` result. All the clusters running with the `anonymous-auth` Kubernetes API Server setting disable (set to `false`) are affected since it would be possible to bypass the token review mechanism, interacting with the upper Kubernetes API Server. This privilege escalation cannot be exploited if you're relying only on client certificates (SSL/TLS). This vulnerability has been addressed in version 0.4.6. Users are advised to upgrade.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-fpvw-6m5v-hqfp

около 2 лет назад

Capsule Proxy Authentication bypass using an empty token

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-48312

capsule-proxy is a reverse proxy for the capsule operator project. Affected versions are subject to a privilege escalation vulnerability which is based on a missing check if the user is authenticated based on the `TokenReview` result. All the clusters running with the `anonymous-auth` Kubernetes API Server setting disable (set to `false`) are affected since it would be possible to bypass the token review mechanism, interacting with the upper Kubernetes API Server. This privilege escalation cannot be exploited if you're relying only on client certificates (SSL/TLS). This vulnerability has been addressed in version 0.4.6. Users are advised to upgrade.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-fpvw-6m5v-hqfp

Capsule Proxy Authentication bypass using an empty token

CVSS3: 9.8
0%
Низкий
около 2 лет назад

Уязвимостей на страницу