CVE-2023-36815

CVSS Score of 10 (low)

Details

Published Jul 3, 2023
Updated: Jul 10, 2023
CWE ID 862

Summary

CVE-2023-36815 is a vulnerability in the Sealos Cloud Operating System, specifically in version 4.2.0 and earlier. The flaw exists in the billing system of Sealos, allowing users to control the recharge resource account `sealos[.] io/v1/Payment` and potentially recharge any amount of 1 renminbi (RMB). This vulnerability may expose resource information through the charging interface. The user's namespace of this custom resource can be manipulated, but it is unclear if a fix is available at this time. The vulnerability has a high severity rating and poses a risk to organizations, with the potential for unauthorized recharging and potential impact on integrity and confidentiality.

Share

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-36815 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options