peter bassill · operator
$ cve CVE-2024-46528 JSON

CVE-2024-46528 EXPLOIT

4.3
MEDIUM · CVSS 3.1 · EPSS 1.6% (pctl 75)

Patch early

A public exploit exists.

Description

An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through 3.5.0 allows low-privileged authenticated attackers to access sensitive resources without proper authorization checks.

Scoring

CVSS4.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS1.58% — more likely to be exploited than 75% of all CVEs
WeaknessCWE-639
On CISA KEVno
Public exploityes
Published2024-10-14
Last modified2026-06-17

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD