Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-45933

71
FAUCET Score

CVE-2022-45933 is a critical authentication bypass vulnerability affecting KubeView through version 0.1.31, allowing unauthenticated attackers to gain full control of a Kubernetes cluster by accessing certificate files via the api/scrape/kube-system endpoint. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this flaw presents a severe risk due to its network-based attack vector, low complexity, and complete compromise potential. While not currently on CISA's KEV catalog or showing active exploitation, public Nuclei templates exist, and the vendor acknowledges the project's lack of security, underscoring the importance of immediate mitigation for affected systems.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.1.31CPE matchmatch criteria
cpe:2.3:a:kubeview_project:kubeview:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
51.70%
Probability of exploitation in next 30 days
EPSS Percentile
98.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
Nuclei: CVE-2022-45933 · Nov 29, 2022
This CVE's current EPSS score of 0.5170 is in the 97th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

goGHSA-22vc-5pgw-644qcritical

KubeView vulnerable to full cluster takeover due to improper authentication

Nov 27, 2022

References

github.com / benc-uk/kubeview/issues/95
ExploitIssue TrackingThird Party Advisory