Laf env causes sensitive information disclosure
CVE-2023-48225
8.9HIGH
What is CVE-2023-48225?
The Laf Cloud Development Platform is susceptible to a vulnerability that allows unauthorized access to sensitive information, specifically secrets and config maps, due to insufficient control over environment variables in privatized environments. In versions prior to 1.0.0-beta.13, environmental settings can be improperly handled, potentially revealing critical data through the k8s envFrom field when namespace configuration is fixed. This flaw arises from the method by which application deployment instances reference database-stored environment variables, risking exposure of sensitive details in the app's configuration.
Affected Version(s)
laf < 1.0.0-beta13
