CVE-2023-50253
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 3, 2024
Updated: Jan 11, 2024
CWE ID 200
CWE ID 532
Summary
CVE-2023-50253 is a vulnerability affecting the Laf cloud development platform. In versions 1.0.0-beta.13 and older, the platform's log retrieval interface, which communicates with k8s to quickly retrieve logs from containers, fails to verify the permissions of the pod. This issue allows authenticated users to access any pod logs under the same namespace, potentially exposing sensitive information printed in the logs. Currently, there are no patched versions available to address this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- La-F
Affected Vendors
- LAF