VYPR

Kubesphere

by Kubesphere

Source repositories

CVEs (2)

  • CVE-2026-71208MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery.ServerVersion against the CRD-specified Kubernetes API endpoint, which is…

  • CVE-2024-46528MedOct 14, 2024
    risk 0.24cvss 4.3epss 0.02

    An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through 3.5.0 allows low-privileged authenticated attackers to access sensitive resources without proper authorization…