CRITICAL
KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin
Published Nov 27, 2022
9.8
CRITICALCVSS 3.1
EPSS 51.70%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.