Skip to content

Sealos billing system permission control defect

High
zzjin published GHSA-vpxf-q44g-w34w Jun 30, 2023

Package

sealos (sealos)

Affected versions

< 4.2.0

Patched versions

None

Description

Summary

There is a permission flaw in the Sealos billing system, which allows users to control the recharge resource account. sealos. io/v1/Payment, resulting in the ability to recharge any amount of 1 RMB.

Details

The reason is that sealos is in arrears. Egg pain, we can't create a terminal anymore. Let's charge for it:

Then it was discovered that the charging interface had returned all resource information. Unfortunately, based on previous vulnerability experience, the namespace of this custom resource is still under the current user's control and may have permission to correct it.

PoC

disable by publish

Impact

  • sealos public cloud user
  • CWE-287 Improper Authentication

Severity

High
7.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

CVE ID

CVE-2023-36815

Weaknesses

Credits