Record summary

CVE-2018-18264 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHKubernetes Dashboard <1.10.1 - Authentication BypassCVSS 7.5

Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.

Impact

An attacker can bypass authentication and gain unauthorized access to the Kubernetes Dashboard, potentially leading to further compromise of the Kubernetes cluster.

Remediation

Upgrade to Kubernetes Dashboard version 1.10.1 or later to mitigate the authentication bypass vulnerability.

WeaknessesCWE-306
Authorsedoardottt
Template tagscvecve2018kubernetesk8sauth-bypassvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:kubernetes:dashboard:*:*:*:*:*:*:*:*
Shodan: product:"Kubernetes"
Shodan: product:"kubernetes"

Source: ProjectDiscovery

References

7