Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS03NGo4LXc3ZjktcHA2Ms4AA0KE
Improper configuration of RBAC permissions obtaining cluster control permissions
Summary
Improper configuration of RBAC permissions resulted in obtaining cluster control permissions, which could control the entire cluster deployed with Sealos, as well as hundreds of pods and other resources within the cluster.
Details
detail's is disable by publish.
PoC
detail's is disable by publish.
Impact
- sealos public cloud user
- CWE-287 Improper Authentication
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03NGo4LXc3ZjktcHA2Ms4AA0KE
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: 3 months ago
Updated: 3 months ago
CVSS Score: 9.9
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Identifiers: GHSA-74j8-w7f9-pp62, CVE-2023-33190
References:
- https://github.com/labring/sealos/security/advisories/GHSA-74j8-w7f9-pp62
- https://nvd.nist.gov/vuln/detail/CVE-2023-33190
- https://github.com/labring/sealos/commit/4cdf52e55666864e5f90ed502e9fc13e18985b7b
- https://github.com/advisories/GHSA-74j8-w7f9-pp62
Affected Packages
go:github.com/labring/sealos
Versions: < 4.2.1-rc4Fixed in: 4.2.1-rc4