CVE-2023-48225
Last modified
CVE-2023-48225 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Laf is a cloud development platform. Prior to version 1.0.0-beta.13, the control of LAF app enV is not strict enough, and in certain scenarios of privatization environment, it may lead to sensitive information leakage in secret and configmap. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
Laf is a cloud development platform. Prior to version 1.0.0-beta.13, the control of LAF app enV is not strict enough, and in certain scenarios of privatization environment, it may lead to sensitive information leakage in secret and configmap. In ES6 syntax, if an obj directly references another obj, the name of the obj itself will be used as the key, and the entire object structure will be integrated intact. When constructing the deployment instance of the app, env was found from the database and directly inserted into the template, resulting in controllability here. Sensitive information in the secret and configmap can be read through the k8s envFrom field. In a privatization environment, when `namespaceConf. fixed` is marked, it may lead to the leakage of sensitive information in the system. As of time of publication, it is unclear whether any patches or workarounds exist.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Laf | Laf | 0.1.5 | — |
| Laf | Laf | 0.4.0 | — |
| Laf | Laf | 0.4.1 | — |
| Laf | Laf | 0.4.2 | — |
| Laf | Laf | 0.4.3 | — |
| Laf | Laf | 0.4.4 | — |
| Laf | Laf | 0.4.5 | — |
| Laf | Laf | 0.4.6 | — |
| Laf | Laf | 0.4.7 | — |
| Laf | Laf | 0.4.8 | — |
| Laf | Laf | 0.4.9 | — |
| Laf | Laf | 0.4.10 | — |
| Laf | Laf | 0.4.11 | — |
| Laf | Laf | 0.4.12 | — |
| Laf | Laf | 0.4.13 | — |
| Laf | Laf | 0.4.14 | — |
| Laf | Laf | 0.4.15 | — |
| Laf | Laf | 0.4.16 | — |
| Laf | Laf | 0.4.17 | — |
| Laf | Laf | 0.4.18 | — |
| Laf | Laf | 0.4.19 | — |
| Laf | Laf | 0.4.20 | — |
| Laf | Laf | 0.4.21 | Alpha0 |
| Laf | Laf | 0.5.0 | — |
| Laf | Laf | 0.5.1 | — |
| Laf | Laf | 0.5.2 | — |
| Laf | Laf | 0.5.3 | — |
| Laf | Laf | 0.5.4 | — |
| Laf | Laf | 0.5.5 | — |
| Laf | Laf | 0.5.6 | — |
| Laf | Laf | 0.5.7 | — |
| Laf | Laf | 0.5.8 | Alpha0 |
| Laf | Laf | 0.6.0 | — |
| Laf | Laf | 0.6.1 | — |
| Laf | Laf | 0.6.2 | — |
| Laf | Laf | 0.6.3 | — |
| Laf | Laf | 0.6.4 | — |
| Laf | Laf | 0.6.5 | — |
| Laf | Laf | 0.6.6 | — |
| Laf | Laf | 0.6.7 | — |
| Laf | Laf | 0.6.8 | — |
| Laf | Laf | 0.6.9 | — |
| Laf | Laf | 0.6.10 | — |
| Laf | Laf | 0.6.11 | — |
| Laf | Laf | 0.6.12 | — |
| Laf | Laf | 0.6.13 | — |
| Laf | Laf | 0.6.14 | — |
| Laf | Laf | 0.6.15 | — |
| Laf | Laf | 0.6.16 | — |
| Laf | Laf | 0.6.17 | — |
Showing 50 of 83 affected configurations. See NVD for the full list.
References
- https://github.com/labring/laf/security/advisories/GHSA-hv2g-gxx4-fwxpExploit, Third Party Advisory
- https://github.com/labring/laf/security/advisories/GHSA-hv2g-gxx4-fwxpExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-48225?
How severe is CVE-2023-48225?
How do I fix CVE-2023-48225?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-4822Grafana is an open-source platform for monitoring and observ…7.2
- CVE-2023-48220Decidim is a participatory democracy framework. Starting in …7.4
- CVE-2023-48221wire-avs provides Audio, Visual, and Signaling (AVS) functio…8.8
- CVE-2023-48222Rundeck is an open source automation service with a web cons…5.4
- CVE-2023-48223fast-jwt provides fast JSON Web Token (JWT) implementation. …5.9
- CVE-2023-48224Fides is an open-source privacy engineering platform for man…9.1
- CVE-2023-48226OpenReplay is a self-hosted session replay suite. In version…3.5
- CVE-2023-48227Umbraco is an ASP.NET content management system (CMS). Start…4.3
- CVE-2023-48228authentik is an open-source identity provider. When initiali…9.8
- CVE-2023-48229Contiki-NG is an open-source, cross-platform operating syste…7.6
- CVE-2023-4823The WP Meta and Date Remover WordPress plugin before 2.2.0 p…5.4
- CVE-2023-48230Cap'n Proto is a data interchange format and capability-base…9.8
Are you affected by CVE-2023-48225?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
