Impact
Kubero versions up to 3.1.1 do not enforce authentication on the notifications API, allowing attackers to retrieve stored webhook secrets and service URLs. The exposed information includes credentials that could be used to impersonate legitimate webhooks, intercept pipeline events, or delete existing configurations, effectively compromising both confidentiality and integrity of the deployment. The vulnerability is categorized under CWE-306, indicating a failure to check authentication before allowing an operation.
Affected Systems
The impact applies to all installations of Kubero built from the kubero-dev/kubero code base with a version of 3.1.1 or earlier. No specific sub‑version or build is listed, so the entire 3.1.1 release is affected.
Risk and Exploitability
The CVSS score of 9.3 reflects a high severity – an unauthenticated attacker can gain significant knowledge of the system and alter webhook behavior. EPSS indicates the likelihood of exploitation is very low (< 1 %), yet the absence from the CISA KEV catalog suggests no widespread exploitation has been reported to date. An attacker could exploit this via unauthenticated HTTP requests to the /notifications endpoints, provided network reachability to the Kubero instance.
OpenCVE Enrichment