KubePi Privilege Escalation vulnerability
Description
Published to the GitHub Advisory Database
Jul 21, 2023
Reviewed
Jul 21, 2023
Published by the National Vulnerability Database
Jul 21, 2023
Last updated
Nov 8, 2023
Summary
A normal user has permission to create/update users, they can become admin by editing the
isadmin
value in the requestPoC
Change the value of the
isadmin
field in the request to true:https://drive.google.com/file/d/1e8XJbIFIDXaFiL-dqn0a0b6u7o3CwqSG/preview
Impact
Elevate user privileges
References