Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
KubePi vulnerable to session fixation attack
Vulnerability Description
KubePi is a modern Kubernetes panel. A session fixation attack allows an attacker to hijack a legitimate user session, versions 1.6.3 and below are susceptible. A patch will be released in version 1.6.4.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
会话固定
Vulnerability Title
KubePi 授权问题漏洞
Vulnerability Description
KubePi是一个K8s面板。它允许管理员导入多个Kubernetes集群,并且通过权限控制,将不同cluster、namespace的权限分配给指定用户。 KubePi 1.6.3及之前版本存在授权问题漏洞,该漏洞源于会话固定攻击允许攻击者劫持合法用户会话,该攻击调查了在线应用程序处理会话 ID 的方式中的缺陷,尤其是易受攻击的 Web 应用程序。
CVSS Information
N/A
Vulnerability Type
N/A