Sealos is a Cloud Operating System designed for managing cloud-native applications. In version 4.2.0 and prior, there is a permission flaw in the Sealos billing system, which allows users to control the recharge resource account `sealos[.] io/v1/Payment`, resulting in the ability to recharge any amount of 1 renminbi (RMB). The charging interface may expose resource information. The namespace of this custom resource would be user's control and may have permission to correct it. It is not clear whether a fix exists.
History

Wed, 06 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-11-06T17:01:26.967Z

Reserved: 2023-06-27T15:43:18.384Z

Link: CVE-2023-36815

cve-icon Vulnrichment

Updated: 2024-08-02T17:01:09.546Z

cve-icon NVD

Status : Modified

Published: 2023-07-03T18:15:09.653

Modified: 2024-11-21T08:10:39.377

Link: CVE-2023-36815

cve-icon Redhat

No data.