PT-2023-30775 · Unknown · Capsule-Proxy

Luisdavim

+1

·

Published

2023-11-24

·

Updated

2024-08-21

·

CVE-2023-48312

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions capsule-proxy versions prior to 0.4.6
Description The issue is a privilege escalation vulnerability based on a missing check if the user is authenticated based on the TokenReview result. This affects clusters running with the anonymous-auth Kubernetes API Server setting disabled (set to false), allowing bypass of the token review mechanism and interaction with the upper Kubernetes API Server. The vulnerability cannot be exploited if relying only on client certificates (SSL/TLS).
Recommendations For versions prior to 0.4.6, upgrade to version 0.4.6 to address the vulnerability. As a temporary workaround, consider disabling the anonymous-auth feature or restricting access to the capsule-proxy until the issue is resolved. Restrict access to the Kubernetes API Server to minimize the risk of exploitation. Avoid using empty tokens in the Authorization header until the issue is resolved.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-48312
GHSA-FPVW-6M5V-HQFP
GO-2023-2351

Affected Products

Capsule-Proxy