GHSA-74j8-w7f9-pp62
Dashboard / Vulnerabilities / GHSA-74j8-w7f9-pp62
Summary: Improper configuration of RBAC permissions obtaining cluster control permissions
Details: ### Summary Improper configuration of RBAC permissions resulted in obtaining cluster control permissions, which could control the entire cluster deployed with Sealos, as well as hundreds of pods and other resources within the cluster. ### Details detail's is disable by publish. ### PoC detail's is disable by publish. ### Impact + sealos public cloud user + CWE-287 Improper Authentication
References: https://github.com/labring/sealos/security/advisories/GHSA-74j8-w7f9-pp62, https://nvd.nist.gov/vuln/detail/CVE-2023-33190, https://github.com/labring/sealos/commit/4cdf52e55666864e5f90ed502e9fc13e18985b7b, https://github.com/labring/sealos
Affected packages
Package
Name: github.com/labring/sealos
Purl: pkg:golang/github.com/labring/sealos
Affected ranges
Type: SEMVER
Events:
