CVE-2024-46528 EXPLOIT
4.3
MEDIUM · CVSS 3.1 · EPSS 1.6% (pctl 75)
Patch early
A public exploit exists.
Description
An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through 3.5.0 allows low-privileged authenticated attackers to access sensitive resources without proper authorization checks.
Scoring
| CVSS | 4.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 1.58% — more likely to be exploited than 75% of all CVEs |
| Weakness | CWE-639 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2024-10-14 |
| Last modified | 2026-06-17 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | KubeSphere 3.4.0 - Insecure Direct Object Reference (IDOR) | 2025-03-27 |
References
→ the Explorer · watch your stack · NVD