← Back to browse · API

CVE-2022-45933

Severity
CRITICAL
CVSS
9.8
EPSS
0.51696
Risk score
57.29
CISA KEV
No
PoC
No
Published
2022-11-27
Modified
2025-04-29
First seen
2026-08-07
Aliases
EUVD-2022-7188, GHSA-22VC-5PGW-644Q
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-7188

Description

KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."

References