Vulnerability record · CVE-2022-45933 · published 27 November 2022
CVE-2022-45933: KubeView unauthenticated scrape endpoint exposes cluster admin certificates
KKubeview Project · Kubeview
KubeView through 0.1.31 exposes the api/scrape/kube-system endpoint without authentication, and that endpoint retrieves certificate files usable to authenticate as kube-admin. Because the exposed material is cluster-admin credentialing, any reachable instance effectively hands over control of the Kubernetes cluster. The vendor has stated the project was a side project and not intended to be secure, so no fix should be assumed from the vendor.
Description
KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network access yields cluster-admin control of Kubernetes, with a 9.8 CVSS score and high EPSS despite no KEV listing.
What it is
KubeView through 0.1.31 exposes the api/scrape/kube-system endpoint without authentication, and that endpoint retrieves certificate files usable to authenticate as kube-admin. Because the exposed material is cluster-admin credentialing, any reachable instance effectively hands over control of the Kubernetes cluster. The vendor has stated the project was a side project and not intended to be secure, so no fix should be assumed from the vendor.
Impact
An unauthenticated attacker gains cluster-admin credentials and can take full control of the Kubernetes cluster, including reading secrets, modifying workloads and persisting access.
Attack surface
Reachable over the network via the KubeView HTTP service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and the missing-authentication CWE indicate no credentials and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.51696 (98.9th percentile) and both references are tagged Exploit, indicating public exploit material exists and exploitation is plausible.
What to do
- Remove or isolate KubeView instances that cannot be upgraded; the vendor does not treat this as a supported secure product.
- If KubeView must remain, place it behind an authenticating reverse proxy and restrict network access to trusted operators only.
- Rotate any kube-admin or cluster-admin certificates and tokens that may have been exposed through the scrape endpoint.
- Audit and restrict the service account and RBAC permissions granted to KubeView so it cannot read cluster-admin credential material.
- Monitor for and block external access to the api/scrape/kube-system path at the ingress or WAF layer.
Detection
- Search HTTP access logs for requests to api/scrape/kube-system, especially from unexpected or external source IPs.
- Alert on Kubernetes API authentication using kube-admin or other cluster-admin certificates from unusual source addresses.
- Monitor for creation of new cluster-admin role bindings, service accounts or tokens that could indicate post-exploitation persistence.
- Inventory running KubeView instances and flag any version at or below 0.1.31 exposed beyond localhost.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/benc-uk/kubeview/issues/95 | ExploitIssue TrackingThird Party Advisory |
| https://github.com/benc-uk/kubeview/issues/95 | ExploitIssue TrackingThird Party Advisory |
Track CVE-2022-45933 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-45933), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.