{"id":"CVE-2023-22480","aliases":["GHSA-jxgp-jgh3-8jc8"],"url":"https://o3.security/vulnerability/CVE-2023-22480","summary":"KubeOperator is vulnerable to unauthorized access to system API","details":"### Summary\n\nUnauthorized access refers to the ability to bypass the system's preset permission settings to access some API interfaces. The attack exploits a flaw in how online applications handle routing permissions.\n\n### Affected Version\n\n<= v3.16.3\n\n### Patches\n\nThe vulnerability has been fixed in v3.16.3.\n\nhttps://github.com/KubeOperator/KubeOperator/commit/7ef42bf1c16900d13e6376f8be5ecdbfdfb44aaf\n\n### Workarounds\n\nIt is recommended to upgrade the version to v3.16.4.\n\n### For more information\n\nIf you have any questions or comments about this advisory, please open an issue.\n\n### References\n\nhttps://github.com/KubeOperator/KubeOperator/releases/tag/v3.16.4","published":"2023-01-14T00:03:19.245Z","modified":"2026-08-12T03:51:20.936013825Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":{"score":0.66768,"percentile":0.99261,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/KubeOperator/KubeOperator","fixedVersion":null}],"fix":{"url":"https://github.com/KubeOperator/KubeOperator/commit/7ef42bf1c16900d13e6376f8be5ecdbfdfb44aaf","label":"KubeOperator/KubeOperator@7ef42bf"},"references":[{"type":"WEB","url":"https://github.com/KubeOperator/KubeOperator/releases/tag/v3.16.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/22xxx/CVE-2023-22480.json"},{"type":"ADVISORY","url":"https://github.com/KubeOperator/KubeOperator/security/advisories/GHSA-jxgp-jgh3-8jc8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-22480"},{"type":"FIX","url":"https://github.com/KubeOperator/KubeOperator/commit/7ef42bf1c16900d13e6376f8be5ecdbfdfb44aaf"},{"type":"PACKAGE","url":"https://github.com/KubeOperator/KubeOperator"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:20.936013825Z"}}