Karmada Dashboard, Authentication Bypass, CVE-2024-xxxx (Critical)

Listen to this Post

The CVE describes an authentication bypass vulnerability within the Karmada Dashboard’s API layer. The web interface correctly required a JWT token for user interaction, but the underlying backend API endpoints, such as `/api/v1/secret` and /api/v1/service, lacked any authentication middleware. This design flaw completely separated the UI’s authentication from the API’s access control. Consequently, any unauthenticated user with network reachability to the Karmada Dashboard service could send direct HTTP requests (e.g., using curl) to these endpoints. The API would then respond with sensitive Kubernetes cluster data, including Secrets and Services, without challenging the requestor for any credentials, leading to a full compromise of sensitive information.
Platform: Karmada Dashboard
Version: < v0.2.0
Vulnerability: Authentication Bypass
Severity: Critical

date: 2024-xx-xx

Prediction: Patch Available

What Undercode Say:

curl -X GET http://<karmada-dashboard-ip>:8080/api/v1/secret
kubectl get networkpolicies -n karmada-dashboard
kubectl edit deployment karmada-dashboard -n karmada-system

How Exploit:

Direct API requests to `/api/v1/secret` and `/api/v1/service` endpoints without any authentication token.

Protection from this CVE

Upgrade to v0.2.0. Implement network policies. Use authentication reverse proxy.

Impact:

Unauthenticated sensitive data retrieval. Full secret exposure. Cluster information leak.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top