CVE-2023-22480
HIGH NUCLEIFit2cloud Kubeoperator < 3.16.4 - Incorrect Authorization
Title source: ruleDescription
KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This vulnerability could be used to take over the cluster under certain conditions. This issue has been patched in version 3.16.4.
Nuclei Templates (1)
KubeOperator Foreground `kubeconfig` - File Download
CRITICALVERIFIEDby DhiyaneshDk
Shodan:
html:"KubeOperator" || http.html:"kubeoperator"
FOFA:
app="KubeOperator" || body="kubeoperator" || app="kubeoperator"
Scores
CVSS v3
7.3
EPSS
0.7559
EPSS Percentile
98.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-285
CWE-863
Status
published
Products (2)
fit2cloud/kubeoperator
< 3.16.4
KubeOperator/KubeOperator
0Go
Published
Jan 14, 2023
Tracked Since
Feb 18, 2026