CVE-2023-22479

Session Fixation in go/github.com/KubeOperator/KubePi

Identifiers

CVE-2023-22479, GHSA-v4w5-r2xc-7f8h

Package Slug

go/github.com/KubeOperator/KubePi

Vulnerability

Session Fixation

Description

KubePi is a modern Kubernetes panel. A session fixation attack allows an attacker to hijack a legitimate user session, versions 1.6.3 and below are susceptible. A patch will be released in version 1.6.4.

Affected Versions

All versions before 1.6.4

Solution

Upgrade to version 1.6.4 or above.

Last Modified

2023-01-15

source