Record summary

CVE-2023-22480 has a selected CVSS score of 7.3 (high); EIP currently links 1 Nuclei template.

Description

KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This vulnerability could be used to take over the cluster under certain conditions. This issue has been patched in version 3.16.4.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List<= 3.16.3affected

github.com/KubeOperator/KubeOperator

Browse Go / github.com/KubeOperator/KubeOperator
GitHub AdvisoryThrough 3.16.3affected

Nuclei templates

1
ProjectDiscoveryCRITICALKubeOperator Foreground `kubeconfig` - File DownloadCVSS 9.8

KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This vulnerability could be used to take over the cluster under certain conditions. This issue has been patched in version 3.16.4.

Impact

An attacker can download sensitive files from the KubeOperator Foreground kubeconfig file, potentially leading to unauthorized access or exposure of sensitive information.

Remediation

Upgrade to the latest version to mitigate this vulnerability.

WeaknessesCWE-863CWE-285
AuthorsDhiyaneshDk
Template tagscve2023cvekubeoperatork8skubeconfigexposurefit2cloudvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:fit2cloud:kubeoperator:*:*:*:*:*:*:*:*
Shodan: html:"KubeOperator"
Shodan: http.html:"kubeoperator"
FOFA: app="KubeOperator"
FOFA: body="kubeoperator"
FOFA: app="kubeoperator"

Source: ProjectDiscovery

References

5