Privilege Escalation Affecting github.com/1panel-dev/kubepi/internal/service/v1/user package, versions <1.6.5


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.11% (47th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOM1PANELDEVKUBEPIINTERNALSERVICEV1USER-5803018
  • published23 Jul 2023
  • disclosed21 Jul 2023
  • creditPhạm Đăng Chính

Introduced: 21 Jul 2023

CVE-2023-37917  (opens in a new tab)
CWE-264  (opens in a new tab)

How to fix?

Upgrade github.com/1Panel-dev/KubePi/internal/service/v1/user to version 1.6.5 or higher.

Overview

Affected versions of this package are vulnerable to Privilege Escalation. This is exploitable because a normal user have permission to create/update users, allowing them to become admin by editing the isadmin value in the request

CVSS Scores

version 3.1