GHSA-22vc-5pgw-644q

Source
https://github.com/advisories/GHSA-22vc-5pgw-644q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-22vc-5pgw-644q/GHSA-22vc-5pgw-644q.json
Aliases
Published
2022-11-27T03:30:25Z
Modified
2023-11-08T04:10:54.371197Z
Details

KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."

References

Affected packages

Go / github.com/benc-uk/kubeview

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Last affected
0.1.31