CVE-2023-22478: KubePi is vulnerable to missing authorization

Published Jan 9, 2023
·
Updated

Summary Unauthorized access refers to the ability to bypass the system's preset permission settings to access some API interfaces. The attack exploits a flaw in how online applications handle routing permissions.

Affected Version <= v1.6.3

Patches The vulnerability has been fixed in v1.6.4.

https://github.com/KubeOperator/KubePi/commit/0c6774bf5d9003ae4d60257a3f207c131ff4a6d6

Workarounds It is recommended to upgrade the version to v1.6.4.

For more information If you have any questions or comments about this advisory, please open an issue.

References https://github.com/KubeOperator/KubePi/releases/tag/v1.6.4

Other sources

KubePi is a modern Kubernetes panel. The API interfaces with unauthorized entities and may leak sensitive information. This issue has been patched in version 1.6.4. There are currently no known workarounds.

Affected Software

2 affected componentsFixes available
go/github.com/KubeOperator/kubepi<=1.6.3
1.6.4
FIT2CLOUD Kubepi<1.6.4

Event History

Jan 9, 2023
Advisory Published
09:56 PM
Jan 14, 2023
CVE Published
via MITRE·12:22 AM
Data Sourced
via MITRE·12:22 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability ID for KubePi?

The vulnerability ID for KubePi is CVE-2023-22478.

2

What is the severity rating of CVE-2023-22478?

CVE-2023-22478 has a severity rating of 7.5 (high).

3

How does the vulnerability in KubePi occur?

The vulnerability in KubePi occurs due to unauthorized access, allowing bypass of preset permission settings to access certain API interfaces.

4

Which version(s) of KubePi are affected by CVE-2023-22478?

Versions up to v1.6.3 of KubePi are affected by CVE-2023-22478.

5

How can I patch the vulnerability in KubePi?

The vulnerability has been fixed in version 1.6.4 of KubePi, so upgrading to this version or later is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203