Vulnerability record · CVE-2023-22480 · published 14 January 2023
CVE-2023-22480: KubeOperator API improper authorization allows cluster takeover
Fit2cloud · Kubeoperator
KubeOperator versions 3.16.3 and below expose API interfaces to unauthorized entities, leaking sensitive information. The improper authorization can, under certain conditions, be used to take over the managed Kubernetes cluster. The issue is patched in version 3.16.4.
Description
KubeOperator is an open source Kubernetes distribution focused on helping enterprises plan, deploy and operate production-level K8s clusters. In KubeOperator versions 3.16.3 and below, API interfaces with unauthorized entities and can leak sensitive information. This vulnerability could be used to take over the cluster under certain conditions. This issue has been patched in version 3.16.4.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required and a very high EPSS score, plus potential full cluster takeover.
What it is
KubeOperator versions 3.16.3 and below expose API interfaces to unauthorized entities, leaking sensitive information. The improper authorization can, under certain conditions, be used to take over the managed Kubernetes cluster. The issue is patched in version 3.16.4.
Impact
An unauthenticated attacker can reach API endpoints and obtain sensitive information, and under certain conditions use that access to take over the cluster.
Attack surface
Reachable over the network via the KubeOperator API; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is high at 0.668 (99.3rd percentile), indicating elevated likelihood of exploitation; references are patch and advisory only, with no public exploit tag.
What to do
- Upgrade KubeOperator to version 3.16.4 or later, which contains the patch.
- Restrict network access to the KubeOperator API to trusted management networks only.
- Audit API-facing deployments for unauthorized access and rotate any credentials or tokens that may have been exposed.
- Review cluster-level permissions and service accounts for signs of unauthorized use.
Detection
- Monitor KubeOperator API logs for requests to sensitive endpoints from unexpected or unauthenticated sources.
- Alert on anomalous authentication failures or access patterns against the KubeOperator API.
- Watch for unexpected changes to cluster configuration, RBAC or service accounts that could indicate takeover attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/KubeOperator/KubeOperator/commit/7ef42bf1c16900d13e6376f8be5ecdbfdfb44aaf | PatchThird Party Advisory |
| https://github.com/KubeOperator/KubeOperator/releases/tag/v3.16.4 | Release NotesThird Party Advisory |
| https://github.com/KubeOperator/KubeOperator/security/advisories/GHSA-jxgp-jgh3-8jc8 | PatchThird Party Advisory |
| https://github.com/KubeOperator/KubeOperator/commit/7ef42bf1c16900d13e6376f8be5ecdbfdfb44aaf | PatchThird Party Advisory |
| https://github.com/KubeOperator/KubeOperator/releases/tag/v3.16.4 | Release NotesThird Party Advisory |
| https://github.com/KubeOperator/KubeOperator/security/advisories/GHSA-jxgp-jgh3-8jc8 | PatchThird Party Advisory |
Track CVE-2023-22480 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-22480), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.