CVE-2023-36815 is a high-severity permission flaw (CVSS 8.1) affecting Sealos versions 4.2.0 and prior, a Cloud Operating System. This vulnerability allows authenticated users to manipulate the billing system, specifically the recharge resource account, enabling them to recharge any amount of 1 RMB and potentially expose resource information. The attack requires low privileges and no user interaction, with a high impact on confidentiality and integrity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2.0CPE matchmatch criteria | cpe:2.3:o:sealos:sealos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.