Record summary

CVE-2023-37916 has a selected CVSS score of 6.5 (medium).

Description

KubePi is an opensource kubernetes management panel. The endpoint /kubepi/api/v1/users/search?pageNum=1&&pageSize=10 leak password hash of any user (including admin). A sufficiently motivated attacker may be able to crack leaded password hashes. This issue has been addressed in version 1.6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 10, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List< 1.6.5affected

Default status: unknown

CVE ListBefore 1.6.5affected

github.com/KubeOperator/kubepi

Browse Go / github.com/KubeOperator/kubepi
GitHub AdvisoryBefore 1.6.5 · Fixed in 1.6.5affected

References

5