Record summary

CVE-2023-37917 has a selected CVSS score of 9.1 (critical).

Description

KubePi is an opensource kubernetes management panel. A normal user has permission to create/update users, they can become admin by editing the `isadmin` value in the request. As a result any user may take administrative control of KubePi. This issue has been addressed in version 1.6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 10, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List< 1.6.5affected

Default status: unknown

CVE ListBefore 1.6.5affected

github.com/KubeOperator/kubepi

Browse Go / github.com/KubeOperator/kubepi
GitHub AdvisoryBefore 1.6.5 · Fixed in 1.6.5affected

References

5