KubePi may leak password hash of any user
Description
Published to the GitHub Advisory Database
Jul 21, 2023
Reviewed
Jul 21, 2023
Published by the National Vulnerability Database
Jul 21, 2023
Last updated
Nov 8, 2023
Summary
http://kube.pi/kubepi/api/v1/users/search?pageNum=1&&pageSize=10 leak password of any user (including admin). This leads to password crack attack
PoC
https://drive.google.com/file/d/1ksdawJ1vShRJyT3wAgpqVmz-Ls6hMA7M/preview
Impact
References