{"id":"GHSA-22vc-5pgw-644q","summary":"KubeView vulnerable to full cluster takeover due to improper authentication","details":"KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a \"fun side project and a learning exercise,\" and not \"very secure.\"","aliases":["CVE-2022-45933"],"modified":"2023-11-08T04:10:54.371197Z","published":"2022-11-27T03:30:25Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-12-02T22:27:39Z","nvd_published_at":"2022-11-27T03:15:00Z","cwe_ids":["CWE-287","CWE-306"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-45933"},{"type":"WEB","url":"https://github.com/benc-uk/kubeview/issues/95"},{"type":"PACKAGE","url":"https://github.com/benc-uk/kubeview"}],"affected":[{"package":{"name":"github.com/benc-uk/kubeview","ecosystem":"Go","purl":"pkg:golang/github.com/benc-uk/kubeview"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.1.31"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-22vc-5pgw-644q/GHSA-22vc-5pgw-644q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}