CVE-2024-46528: Kubesphere

Medium severity, CVSS 4.3. EPSS: 1.6% chance of exploitation in the next 30 days.

An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through 3.5.0 allows low-privileged authenticated attackers to access sensitive resources without proper authorization checks.

Affected products

  • Kubesphere Kubesphere: from 3.0.0, up to and including 3.4.1; from 4.0, before 4.1.3 (fixed in 4.1.3); from 3.0.0, up to and including 3.5.0

Published 2024-10-14. Last modified 2026-06-17.