CVE-2023-46254 is a medium-severity information disclosure vulnerability affecting Clastix Capsule and Capsule-Proxy, specifically when Capsule-Proxy runs with default caching enabled and tenant owners are ServiceAccounts with identical names in different namespaces. This flaw allows a tenant owner to list namespaces belonging to other tenants, potentially exposing sensitive organizational structures. The vulnerability has a CVSS score of 4.3 (medium) due to its network attack vector and low attack complexity, but it only permits information exfiltration without privilege escalation. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.4.5CPE matchmatch criteria | cpe:2.3:a:clastix:capsule:*:*:*:*:*:*:*:* | ||
< 0.4.5CPE matchmatch criteria | cpe:2.3:a:clastix:capsule-proxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.