CVE-2022-45933 is a critical authentication bypass vulnerability affecting KubeView through version 0.1.31, allowing unauthenticated attackers to gain full control of a Kubernetes cluster by accessing certificate files via the api/scrape/kube-system endpoint. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this flaw presents a severe risk due to its network-based attack vector, low complexity, and complete compromise potential. While not currently on CISA's KEV catalog or showing active exploitation, public Nuclei templates exist, and the vendor acknowledges the project's lack of security, underscoring the importance of immediate mitigation for affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.1.31CPE matchmatch criteria | cpe:2.3:a:kubeview_project:kubeview:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.