Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-45933 PoC — KubeView 访问控制错误漏洞

Source
Associated Vulnerability
Title:KubeView 访问控制错误漏洞 (CVE-2022-45933)
Description:KubeView是Ben Coleman个人开发者的一个 Kubernetes 集群可视化器和图形浏览器。 KubeView 0.1.31之前的版本存在访问控制错误漏洞,该漏洞源于其api/ scraper /kube-system不需要身份验证,并检索可以作为kube-admin进行身份验证的证书文件允许攻击者获得Kubernetes集群的控制权。
Description
KubeView through 0.1.31 is susceptible to information disclosure. An attacker can obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication and retrieves certificate files that can be used for authentication as kube-admin. An attacker can thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
File Snapshot

id: CVE-2022-45933 info: name: KubeView <=0.1.31 - Information Disclosure author: For3stCo1d ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.