Authentication bypass using an empty token in capsule-proxy
CVE-2023-48312
9.8CRITICAL
What is CVE-2023-48312?
Capsule Proxy, a reverse proxy for the Capsule Operator project, is exposed to a privilege escalation vulnerability due to a lack of proper authentication checks. Specifically, this issue arises when the TokenReview
result does not adequately verify if the user is authenticated. Clusters using the anonymous-auth
setting disabled face risks since it permits unauthorized interaction with the upper Kubernetes API Server. Notably, this vulnerability can be mitigated if the usage of client certificates (SSL/TLS) is enforced. The issue has been resolved in version 0.4.6, and users are strongly urged to upgrade to this version or later to ensure the security of their systems.
Affected Version(s)
capsule-proxy < 0.4.6