Record summary

CVE-2022-45933 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 25, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 29, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

github.com/benc-uk/kubeview

Browse Go / github.com/benc-uk/kubeview
GitHub AdvisoryThrough 0.1.31affected

Nuclei templates

1
ProjectDiscoveryCRITICALKubeView <=0.1.31 - Information DisclosureCVSS 9.8

KubeView through 0.1.31 is susceptible to information disclosure. An attacker can obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication and retrieves certificate files that can be used for authentication as kube-admin. An attacker can thereby possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

Unauthenticated attackers can access Kubernetes certificate files through the unauthenticated api/scrape/kube-system endpoint, potentially obtaining kube-admin credentials and gaining complete control over the Kubernetes cluster.

Remediation

Upgrade KubeView to a version higher than 0.1.31 to mitigate the information disclosure vulnerability (CVE-2022-45933).

WeaknessesCWE-306
AuthorsFor3stCo1d
Template tagscvecve2022kubeviewkubernetesexposurekubeview_projectvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:kubeview_project:kubeview:*:*:*:*:*:*:*:*
Shodan: http.title:"KubeView"
Shodan: http.title:"kubeview"
Shodan: http.favicon.hash:-379154636
FOFA: icon_hash=-379154636
FOFA: title="kubeview"
Google: intitle:"kubeview"

Source: ProjectDiscovery

References

3