CVE-2024-46528
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through 3.5.0 allows low-privileged authenticated attackers to access sensitive resources without proper authorization checks.
02 / AFFECTED SOFTWARE
Affected packages
25 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere allows low-privileged authenticated attackers to access sensitive resources without proper authorization checks. NOTE: A fix is expected in v4.1.3 in January 2025.
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere v3.4.1 and v4.1.1 allows low-privileged authenticated attackers to access sensitive resources without proper authorization checks.
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through 3.5.0 allows low-privileged authenticated attackers to access sensitive resources without proper authorization checks.
05 / REFERENCES
Further evidence
- https://github.com/advisories/GHSA-p26r-gfgc-c47h
- https://github.com/kubesphere/kubesphere/issues/6227
- https://okankurtulus.com.tr/2024/09/09/idor-vulnerability-in-kubesphere
- https://www.kubesphere.io/news/kubesphere-cve-2024-46528
- https://github.com/kubesphere/kubesphere
- https://kubesphere.io
- https://nvd.nist.gov/vuln/detail/CVE-2024-46528
- https://pkg.go.dev/vuln/GO-2024-3248
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/46xxx/CVE-2024-46528.json
- https://kubesphere.io/
- https://okankurtulus.com.tr/2024/09/09/idor-vulnerability-in-kubesphere/
- https://www.kubesphere.io/news/kubesphere-cve-2024-46528/