Laf env causes sensitive information disclosure
CVE-2023-48225

8.9HIGH

Key Information:

Vendor

labring

Status
Vendor
CVE Published:
12 December 2023

What is CVE-2023-48225?

The Laf Cloud Development Platform is susceptible to a vulnerability that allows unauthorized access to sensitive information, specifically secrets and config maps, due to insufficient control over environment variables in privatized environments. In versions prior to 1.0.0-beta.13, environmental settings can be improperly handled, potentially revealing critical data through the k8s envFrom field when namespace configuration is fixed. This flaw arises from the method by which application deployment instances reference database-stored environment variables, risking exposure of sensitive details in the app's configuration.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

laf < 1.0.0-beta13

References

CVSS V3.1

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.