CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
31.2%
A session fixation attack allows an attacker to hijack a legitimate user session. The attack investigates a flaw in how the online application handles the session ID, especially the susceptible web application.
<= v1.6.3
The vulnerability has been fixed in v1.6.4.
https://github.com/KubeOperator/KubePi/commit/1e9c550356c1a425a742480efcf743d373e98dcb : A session fixation attack allows an attacker to hijack a legitimate user session.
It is recommended to upgrade the version to v1.6.4.
If you have any questions or comments about this advisory, please open an issue.
Vendor | Product | Version | CPE |
---|---|---|---|
kubeoperator | kubepi | * | cpe:2.3:a:kubeoperator:kubepi:*:*:*:*:*:*:*:* |
github.com/1Panel-dev/KubePi/security/advisories/GHSA-v4w5-r2xc-7f8h
github.com/advisories/GHSA-v4w5-r2xc-7f8h
github.com/KubeOperator/KubePi/commit/1e9c550356c1a425a742480efcf743d373e98dcb
github.com/KubeOperator/KubePi/releases/tag/v1.6.4
github.com/KubeOperator/KubePi/security/advisories/GHSA-v4w5-r2xc-7f8h
nvd.nist.gov/vuln/detail/CVE-2023-22479