{"id":"GHSA-74j8-w7f9-pp62","summary":"Improper configuration of RBAC permissions obtaining cluster control permissions","details":"### Summary\nImproper configuration of RBAC permissions resulted in obtaining cluster control permissions, which could control the entire cluster deployed with Sealos, as well as hundreds of pods and other resources within the cluster.\n\n### Details\ndetail's is disable by publish.\n\n### PoC\ndetail's is disable by publish.\n\n### Impact\n+ sealos public cloud user\n+ CWE-287 Improper Authentication\n","aliases":["CVE-2023-33190"],"modified":"2023-11-08T04:12:39.629571Z","published":"2023-06-30T20:25:52Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-06-30T20:25:52Z","nvd_published_at":"2023-06-29T19:15:08Z","cwe_ids":["CWE-287","CWE-863"]},"references":[{"type":"WEB","url":"https://github.com/labring/sealos/security/advisories/GHSA-74j8-w7f9-pp62"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-33190"},{"type":"WEB","url":"https://github.com/labring/sealos/commit/4cdf52e55666864e5f90ed502e9fc13e18985b7b"},{"type":"PACKAGE","url":"https://github.com/labring/sealos"}],"affected":[{"package":{"name":"github.com/labring/sealos","ecosystem":"Go","purl":"pkg:golang/github.com/labring/sealos"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.2.1-rc4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-74j8-w7f9-pp62/GHSA-74j8-w7f9-pp62.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}