S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 9, 2024

CVE-2023-22478 Scanner

CVE-2023-22478 scanner - Unauthorized Access vulnerability in KubePi

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-22478
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in version 1.6.4. There are currently no known workarounds.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
KubePiby KubeOperator
<= 1.6.3
Updated Aug 19, 2026View on NVD →
Detail

KubePi is a modern web-based Kubernetes management platform developed by Fit2Cloud. It is designed to provide users with a simplified and intuitive interface for managing Kubernetes clusters and resources. Organizations and developers use KubePi to streamline their Kubernetes operations, enhance productivity, and improve overall cluster management. It supports various Kubernetes operations, including deployment, monitoring, and logging. KubePi is widely adopted for its user-friendly design and comprehensive features.

The vulnerability in KubePi allows unauthorized access to sensitive information via the LoginLogsSearch API endpoint. This security flaw exposes user data and potentially sensitive operational details of the Kubernetes cluster. Exploiting this vulnerability does not require authentication, making it a critical security concern. It was addressed in version 1.6.4, and users are urged to upgrade to mitigate the risk.

This vulnerability specifically impacts the /kubepi/api/v1/systems/login/logs/search endpoint of KubePi. By sending a specially crafted request to this endpoint, an attacker can retrieve login logs without proper authentication. The exposed information includes API versions, UUIDs, and usernames. The flaw lies in the lack of adequate access controls on this API endpoint. It affects all versions of KubePi up to and including 1.6.4.

Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information, including user login details and operational data of Kubernetes clusters. This can compromise the integrity and confidentiality of the system, leading to further targeted attacks. It poses a significant risk to the security and privacy of KubePi users and their managed Kubernetes environments.

Joining the S4E platform provides you with comprehensive cybersecurity exposure management. By leveraging our sophisticated scanning technology, you'll gain insights into vulnerabilities like the CVE-2023-22478 in KubePi, enhancing your digital security posture. Our platform offers real-time monitoring, timely alerts, and actionable guidance to remediate identified vulnerabilities, safeguarding your digital assets against emerging threats. Become a member today to secure your systems with cutting-edge cyber defense capabilities.

 

References

Solution Advice
  1. Upgrade KubePi to a version higher than v1.6.4 to mitigate the vulnerability.
  2. Regularly review and update access control policies to ensure only authorized users can access sensitive information.
  3. Monitor logs for unusual access patterns that might indicate attempts to exploit this vulnerability.
  4. Follow security best practices for application and infrastructure management to reduce the risk of similar vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-22478 scanner - Unauthorized Access vulnerability in KubePi | S4E