9.1

CVE-2023-48225

Exploit
Laf is a cloud development platform. Prior to version 1.0.0-beta.13, the control of LAF app enV is not strict enough, and in certain scenarios of privatization environment, it may lead to sensitive information leakage in secret and configmap. In ES6 syntax, if an obj directly references another obj, the name of the obj itself will be used as the key, and the entire object structure will be integrated intact. When constructing the deployment instance of the app, env was found from the database and directly inserted into the template, resulting in controllability here. Sensitive information in the secret and configmap can be read through the k8s envFrom field. In a privatization environment, when `namespaceConf. fixed` is marked, it may lead to the leakage of sensitive information in the system. As of time of publication, it is unclear whether any patches or workarounds exist.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LafLaf Version0.1.5
LafLaf Version0.4.0
LafLaf Version0.4.1
LafLaf Version0.4.2
LafLaf Version0.4.3
LafLaf Version0.4.4
LafLaf Version0.4.5
LafLaf Version0.4.6
LafLaf Version0.4.7
LafLaf Version0.4.8
LafLaf Version0.4.9
LafLaf Version0.4.10
LafLaf Version0.4.11
LafLaf Version0.4.12
LafLaf Version0.4.13
LafLaf Version0.4.14
LafLaf Version0.4.15
LafLaf Version0.4.16
LafLaf Version0.4.17
LafLaf Version0.4.18
LafLaf Version0.4.19
LafLaf Version0.4.20
LafLaf Version0.4.21 Updatealpha0
LafLaf Version0.5.0
LafLaf Version0.5.0 Updatealpha0
LafLaf Version0.5.0 Updatealpha1
LafLaf Version0.5.0 Updatealpha2
LafLaf Version0.5.0 Updatealpha3
LafLaf Version0.5.1
LafLaf Version0.5.1 Updatealpha0
LafLaf Version0.5.2
LafLaf Version0.5.2 Updatealpha0
LafLaf Version0.5.3
LafLaf Version0.5.4
LafLaf Version0.5.4 Updatealpha0
LafLaf Version0.5.5
LafLaf Version0.5.5 Updatealpha0
LafLaf Version0.5.6
LafLaf Version0.5.7
LafLaf Version0.5.7 Updatealpha0
LafLaf Version0.5.8 Updatealpha0
LafLaf Version0.6.0
LafLaf Version0.6.0 Updatealpha0
LafLaf Version0.6.0 Updatealpha1
LafLaf Version0.6.0 Updatealpha10
LafLaf Version0.6.0 Updatealpha2
LafLaf Version0.6.0 Updatealpha3
LafLaf Version0.6.0 Updatealpha4
LafLaf Version0.6.0 Updatealpha5
LafLaf Version0.6.0 Updatealpha6
LafLaf Version0.6.0 Updatealpha7
LafLaf Version0.6.0 Updatealpha8
LafLaf Version0.6.0 Updatealpha9
LafLaf Version0.6.1
LafLaf Version0.6.2
LafLaf Version0.6.3
LafLaf Version0.6.4
LafLaf Version0.6.5
LafLaf Version0.6.6
LafLaf Version0.6.7
LafLaf Version0.6.8
LafLaf Version0.6.9
LafLaf Version0.6.10
LafLaf Version0.6.11
LafLaf Version0.6.12
LafLaf Version0.6.13
LafLaf Version0.6.14
LafLaf Version0.6.15
LafLaf Version0.6.16
LafLaf Version0.6.17
LafLaf Version0.6.18
LafLaf Version0.6.19
LafLaf Version0.6.20
LafLaf Version0.6.21
LafLaf Version0.6.22
LafLaf Version0.6.23
LafLaf Version0.7.0
LafLaf Version0.7.1
LafLaf Version0.7.2
LafLaf Version0.7.3
LafLaf Version0.7.4
LafLaf Version0.7.5
LafLaf Version0.7.6
LafLaf Version0.7.7
LafLaf Version0.7.8
LafLaf Version0.7.9
LafLaf Version0.7.10
LafLaf Version0.7.11
LafLaf Version0.8.0
LafLaf Version0.8.0 Updatealpha0
LafLaf Version0.8.0 Updatealpha1
LafLaf Version0.8.0 Updatealpha10
LafLaf Version0.8.0 Updatealpha11
LafLaf Version0.8.0 Updatealpha2
LafLaf Version0.8.0 Updatealpha3
LafLaf Version0.8.0 Updatealpha4
LafLaf Version0.8.0 Updatealpha5
LafLaf Version0.8.0 Updatealpha6
LafLaf Version0.8.0 Updatealpha7
LafLaf Version0.8.0 Updatealpha8
LafLaf Version0.8.0 Updatealpha9
LafLaf Version0.8.1
LafLaf Version0.8.2
LafLaf Version0.8.3
LafLaf Version0.8.4
LafLaf Version0.8.5
LafLaf Version0.8.5 Updatealpha0
LafLaf Version0.8.6
LafLaf Version0.8.7
LafLaf Version0.8.7 Updatealpha0
LafLaf Version0.8.7 Updatealpha1
LafLaf Version0.8.7 Updatealpha2
LafLaf Version0.8.7 Updatealpha3
LafLaf Version0.8.8
LafLaf Version0.8.9
LafLaf Version0.8.10
LafLaf Version0.8.11
LafLaf Version0.8.12
LafLaf Version0.8.13
LafLaf Version1.0.0 Updatealpha0
LafLaf Version1.0.0 Updatealpha1
LafLaf Version1.0.0 Updatealpha2
LafLaf Version1.0.0 Updatealpha3
LafLaf Version1.0.0 Updatealpha4
LafLaf Version1.0.0 Updatealpha5
LafLaf Version1.0.0 Updatealpha6
LafLaf Version1.0.0 Updatebeta0
LafLaf Version1.0.0 Updatebeta1
LafLaf Version1.0.0 Updatebeta10
LafLaf Version1.0.0 Updatebeta11
LafLaf Version1.0.0 Updatebeta12
LafLaf Version1.0.0 Updatebeta13
LafLaf Version1.0.0 Updatebeta2
LafLaf Version1.0.0 Updatebeta3
LafLaf Version1.0.0 Updatebeta4
LafLaf Version1.0.0 Updatebeta5
LafLaf Version1.0.0 Updatebeta6
LafLaf Version1.0.0 Updatebeta7
LafLaf Version1.0.0 Updatebeta8
LafLaf Version1.0.0 Updatebeta9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.364
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
security-advisories@github.com 8.9 2.3 6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.