Sealos billing system permission control defect
CVE-2023-36815
7.3HIGH
What is CVE-2023-36815?
In the Sealos Cloud Operating System, specifically in versions 4.2.0 and earlier, a vulnerability exists within the billing system that allows unauthorized users to manipulate recharge resource accounts. This flaw permits the unauthorized charging of any amount, starting from 1 renminbi (RMB), through the interface at sealos.io/v1/Payment. The exposure of sensitive resource information and the potential for unauthorized control over the associated namespace raise significant security concerns. Currently, it remains uncertain if an effective patch for this vulnerability has been developed.
Affected Version(s)
sealos <= 4.2.0
