CRITICAL

CVE-2023-22463

CVSS v3

9.8

CRITICAL

EPSS Score

91.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. This means that an attacker can forge any jwt token to take over the administrator account of any online project. Furthermore, they may use the administrator to take over the k8s cluster of the target enterprise. `session.go`, the use of hard-coded JwtSigKey, allows an attacker to use this value to forge jwt tokens arbitrarily. The JwtSigKey is confidential and should not be hard-coded in the code. The vulnerability has been fixed in 1.6.3. In the patch, JWT key is specified in app.yml. If the user leaves it blank, a random key will be used. There are no workarounds aside from upgrading.

Technical details

Published
1/4/2023

Frequently asked questions

What is CVE-2023-22463?

KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. This means that an attacker can forge any jwt token to take over the administrator account of any online project. Furthermore, they may use the administrator to take over the k8s cluster of the target enterprise. `session.go`, the use of hard-coded JwtSigKey, allows an attacker to use this value to forge jwt tokens arbitrarily. The JwtSigKey is confidential and should not be hard-coded in the code. The vulnerability has been fixed in 1.6.3. In the patch, JWT key is specified in app.yml. If the user leaves it blank, a random key will be used. There are no workarounds aside from upgrading.

Is CVE-2023-22463 actively exploited?

Active exploitation of CVE-2023-22463 has not been confirmed. The EPSS score is 91.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-22463?

CVE-2023-22463 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-22463 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.