CVE-2023-22463 is a critical authentication bypass vulnerability affecting KubePi versions up to 1.6.2. It stems from the use of a hard-coded JWT signature key (Jwtsigkey), allowing attackers to forge arbitrary JWT tokens. This flaw enables unauthenticated attackers to take over administrator accounts and subsequently compromise the underlying Kubernetes cluster. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk. While not yet in the KEV catalog, exploit code (Nuclei templates) is publicly available, and there is significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.3CPE matchmatch criteria | cpe:2.3:a:fit2cloud:kubepi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.