CVE-2023-37916 is a high-severity information disclosure vulnerability affecting KubePi, an open-source Kubernetes management panel. An unauthenticated attacker can access the /kubepi/api/v1/users/search endpoint to leak password hashes for all users, including administrators. This allows for potential offline cracking of credentials, leading to unauthorized access. While no active exploitation, public exploit code, or significant community discussion has been observed, the vulnerability has been addressed in KubePi version 1.6.5, and users are strongly advised to upgrade as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.5CPE matchmatch criteria | cpe:2.3:a:fit2cloud:kubepi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.