S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2022-45933 Scanner

CVE-2022-45933 scanner - Improper Access Control vulnerability in KubeView

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-45933
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

KubeView is a popular software used for managing Kubernetes clusters. Developed as a side project, this software has gained popularity for its easy-to-use interface and capability to efficiently manage Kubernetes resources. The platform allows administrators to monitor their clusters' health status, view resource utilization data, and interact with different Kubernetes components. With KubeView, administrators can easily keep track of their resources and customize their clusters according to their business requirements.

One of the major vulnerabilities detected in KubeView is CVE-2022-45933. This vulnerability allows attackers to gain control of a Kubernetes cluster. Specifically, the issue arises because the api/scrape/kube-system feature in KubeView does not require authentication. This means that anyone can access the platform and retrieve certificate files that provide them with the necessary privileges to authenticate as kube-admin. This gives perpetrators unrestricted access to administrative functionality, enabling them to manipulate the clusters in any way they like.

When this vulnerability is exploited, it can result in devastating consequences for organizations, including data breaches, privacy violations, and financial losses. Since attackers can manipulate clusters as they please, they can execute unauthorized activities, plant malware, and exfiltrate sensitive data. Additionally, they can seize control of the entire network or demand a ransom to return it to its original state. Therefore, organizations must be vigilant and take swift action to address this issue before it causes any damage.

In conclusion, it is crucial for organizations to stay updated on the latest vulnerabilities affecting their digital assets. Fortunately, the pro features of s4e.io enable administrators to quickly and easily identify potential risks to their infrastructure. By taking proactive measures to mitigate vulnerabilities, organizations can ensure their systems remain secure and protected against evolving threats.

 

REFERENCES

Solution Advice

To mitigate this vulnerability, administrators can take several precautions, including:

  • Enabling authentication for the api/scrape/kube-system feature.
  • Restricting access to the KubeView platform by implementing firewalls and access control.
  • Regularly conducting security audits to detect vulnerabilities and security gaps.
  • Updating their systems and software regularly to fix known vulnerabilities.
  • Training employees on security best practices and raising awareness on how to recognize potential threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.