Record summary

CVE-2023-22478 has a selected CVSS score of 7.3 (high); EIP currently links 1 Nuclei template.

Description

KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in version 1.6.4. There are currently no known workarounds.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 4, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List<= 1.6.3affected
VulnCheckVersion data not supplied

github.com/KubeOperator/kubepi

Browse Go / github.com/KubeOperator/kubepi
GitHub AdvisoryBefore 1.6.4 · Fixed in 1.6.4affected

Nuclei templates

1
ProjectDiscoveryHIGHKubePi <= v1.6.4 LoginLogsSearch - Unauthorized AccessCVSS 7.5

KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in version 1.6.4. There are currently no known workarounds.

Impact

An attacker can gain unauthorized access to sensitive information.

Remediation

Upgrade KubePi to a version higher than v1.6.4 to mitigate the vulnerability.

WeaknessesCWE-862
AuthorsDhiyaneshDk
Template tagscve2023cvekubepik8sexposurefit2cloudvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:fit2cloud:kubepi:*:*:*:*:*:*:*:*
Shodan: html:"kubepi"
Shodan: http.html:"kubepi"
FOFA: kubepi
FOFA: body="kubepi"

Source: ProjectDiscovery

References

6