9.8
CVSSv3

CVE-2022-45933

Published: 27/11/2022 Updated: 08/08/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

KubeView up to and including 0.1.31 allows malicious users to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kubeview project kubeview

Vendor Advisories

Check Point Reference: CPAI-2022-2034 Date Published: 7 Mar 2024 Severity: Critical ...