CVE-2023-22480
KubeOperator is vulnerable to unauthorized access to system API
Record summary
CVE-2023-22480 has a selected CVSS score of 7.3 (high); EIP currently links 1 Nuclei template.
Description
KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This vulnerability could be used to take over the cluster under certain conditions. This issue has been patched in version 3.16.4.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
KubeOperatorBrowse KubeOperator / KubeOperator | CVE List | <= 3.16.3 | affected |
github.com/KubeOperator/KubeOperatorBrowse Go / github.com/KubeOperator/KubeOperator | GitHub Advisory | Through 3.16.3 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALKubeOperator Foreground `kubeconfig` - File DownloadCVSS 9.8
KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This vulnerability could be used to take over the cluster under certain conditions. This issue has been patched in version 3.16.4.
Impact
An attacker can download sensitive files from the KubeOperator Foreground kubeconfig file, potentially leading to unauthorized access or exposure of sensitive information.
Remediation
Upgrade to the latest version to mitigate this vulnerability.
Source: ProjectDiscovery