Impact
KubeSphere versions up to 4.1.3 contain an SSRF vulnerability in the git credential verification endpoint. The endpoint accepts caller–supplied URLs without validation or allowlist restrictions, and error responses can reveal basic‑auth credentials stored in Secrets. An attacker who can authenticate to the cluster can supply malicious URLs that reach internal or private services, potentially exfiltrating credentials used by the cluster or applications.
Affected Systems
KubeSphere, any installation using version 4.1.3 or earlier. The vulnerability is present in all deployments that expose the git credential verification endpoint and have authentication enabled for the cluster.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. The EPSS score is reported as less than 1%, suggesting a low exploitation probability, but the potential for internal credential exfiltration and the absence of a KEV listing keep the vulnerability’s risk posture high. An attacker would need authenticated cluster access to supply arbitrary URLs to the git credential verification endpoint, which would then be resolved to internal endpoints; error handling could return credential data in the response. No publicly available exploit exists, so discovery would rely on internal reconnaissance or manual probing, yet the serious impact justifies immediate mitigation.
OpenCVE Enrichment