CVE-2023-50253

Laf is a cloud development platform. In the Laf version design, the log uses communication with k8s to quickly retrieve logs from the container without the need for additional storage. However, in version 1.0.0-beta.13 and prior, this interface does not verify the permissions of the pod, which allows authenticated users to obtain any pod logs under the same namespace through this method, thereby obtaining sensitive information printed in the logs. As of time of publication, no known patched versions exist.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.6 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
GitHub_MCNA
9.7 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
VendorProductVersion
laflaf
0.1.5
laflaf
0.4.0
laflaf
0.4.1
laflaf
0.4.2
laflaf
0.4.3
laflaf
0.4.4
laflaf
0.4.5
laflaf
0.4.6
laflaf
0.4.7
laflaf
0.4.8
laflaf
0.4.9
laflaf
0.4.10
laflaf
0.4.11
laflaf
0.4.12
laflaf
0.4.13
laflaf
0.4.14
laflaf
0.4.15
laflaf
0.4.16
laflaf
0.4.17
laflaf
0.4.18
laflaf
0.4.19
laflaf
0.4.20
laflaf
0.4.21:alpha0
laflaf
0.5.0
laflaf
0.5.0:alpha0
laflaf
0.5.0:alpha1
laflaf
0.5.0:alpha2
laflaf
0.5.0:alpha3
laflaf
0.5.1
laflaf
0.5.1:alpha0
laflaf
0.5.2
laflaf
0.5.2:alpha0
laflaf
0.5.3
laflaf
0.5.4
laflaf
0.5.4:alpha0
laflaf
0.5.5
laflaf
0.5.5:alpha0
laflaf
0.5.6
laflaf
0.5.7
laflaf
0.5.7:alpha0
laflaf
0.5.8:alpha0
laflaf
0.6.0
laflaf
0.6.0:alpha0
laflaf
0.6.0:alpha1
laflaf
0.6.0:alpha10
laflaf
0.6.0:alpha2
laflaf
0.6.0:alpha3
laflaf
0.6.0:alpha4
laflaf
0.6.0:alpha5
laflaf
0.6.0:alpha6
laflaf
0.6.0:alpha7
laflaf
0.6.0:alpha8
laflaf
0.6.0:alpha9
laflaf
0.6.1
laflaf
0.6.2
laflaf
0.6.3
laflaf
0.6.4
laflaf
0.6.5
laflaf
0.6.6
laflaf
0.6.7
laflaf
0.6.8
laflaf
0.6.9
laflaf
0.6.10
laflaf
0.6.11
laflaf
0.6.12
laflaf
0.6.13
laflaf
0.6.14
laflaf
0.6.15
laflaf
0.6.16
laflaf
0.6.17
laflaf
0.6.18
laflaf
0.6.19
laflaf
0.6.20
laflaf
0.6.21
laflaf
0.6.22
laflaf
0.6.23
laflaf
0.7.0
laflaf
0.7.1
laflaf
0.7.2
laflaf
0.7.3
laflaf
0.7.4
laflaf
0.7.5
laflaf
0.7.6
laflaf
0.7.7
laflaf
0.7.8
laflaf
0.7.9
laflaf
0.7.10
laflaf
0.7.11
laflaf
0.8.0
laflaf
0.8.0:alpha0
laflaf
0.8.0:alpha1
laflaf
0.8.0:alpha10
laflaf
0.8.0:alpha11
laflaf
0.8.0:alpha2
laflaf
0.8.0:alpha3
laflaf
0.8.0:alpha4
laflaf
0.8.0:alpha5
laflaf
0.8.0:alpha6
laflaf
0.8.0:alpha7
laflaf
0.8.0:alpha8
laflaf
0.8.0:alpha9
laflaf
0.8.1
laflaf
0.8.2
laflaf
0.8.3
laflaf
0.8.4
laflaf
0.8.5
laflaf
0.8.5:alpha0
laflaf
0.8.6
laflaf
0.8.7
laflaf
0.8.7:alpha0
laflaf
0.8.7:alpha1
laflaf
0.8.7:alpha2
laflaf
0.8.7:alpha3
laflaf
0.8.8
laflaf
0.8.9
laflaf
0.8.10
laflaf
0.8.11
laflaf
0.8.12
laflaf
0.8.13
laflaf
1.0.0:alpha0
laflaf
1.0.0:alpha1
laflaf
1.0.0:alpha2
laflaf
1.0.0:alpha3
laflaf
1.0.0:alpha4
laflaf
1.0.0:alpha5
laflaf
1.0.0:alpha6
laflaf
1.0.0:beta0
laflaf
1.0.0:beta1
laflaf
1.0.0:beta10
laflaf
1.0.0:beta11
laflaf
1.0.0:beta12
laflaf
1.0.0:beta2
laflaf
1.0.0:beta3
laflaf
1.0.0:beta4
laflaf
1.0.0:beta5
laflaf
1.0.0:beta6
laflaf
1.0.0:beta7
laflaf
1.0.0:beta8
laflaf
1.0.0:beta9
𝑥
= Vulnerable software versions