Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41708
HistoryJul 25, 2023 - 6:07 a.m.

Privilege Escalation

2023-07-2506:07:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
vulnerability
kubeoperator
kubepi
permission restrictions
user actions
software

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

0.001 Low

EPSS

Percentile

23.5%

github.com/kubeoperator/kubepi is vulnerable toPrivilege Escalation . The vulnerability exists due to improper permission restrictions when creating or updating users which allows an attacker to perform authorized actions on users such as changing roles.

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

0.001 Low

EPSS

Percentile

23.5%