CVE-2023-22480 is a critical vulnerability affecting KubeOperator versions 3.16.3 and below, an open-source Kubernetes distribution. It allows unauthorized API access, leading to sensitive information disclosure and potential cluster takeover. With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable over the network with low complexity and can result in complete compromise of confidentiality, integrity, and availability. While not currently on the KEV catalog or showing active exploitation, a Nuclei template exists for detecting the vulnerability, and its high EPSS score indicates a significant likelihood of future exploitation. There is minimal public discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.16.4CPE matchmatch criteria | cpe:2.3:a:fit2cloud:kubeoperator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.