Authentication bypass using an empty token in capsule-proxy
CVE-2023-48312

9.8CRITICAL

Key Information:

Vendor
CVE Published:
24 November 2023

What is CVE-2023-48312?

Capsule Proxy, a reverse proxy for the Capsule Operator project, is exposed to a privilege escalation vulnerability due to a lack of proper authentication checks. Specifically, this issue arises when the TokenReview result does not adequately verify if the user is authenticated. Clusters using the anonymous-auth setting disabled face risks since it permits unauthorized interaction with the upper Kubernetes API Server. Notably, this vulnerability can be mitigated if the usage of client certificates (SSL/TLS) is enforced. The issue has been resolved in version 0.4.6, and users are strongly urged to upgrade to this version or later to ensure the security of their systems.

Affected Version(s)

capsule-proxy < 0.4.6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.