Loading HuntDB...

Broken Link Takeover from kubernetes.io docs

Low
K
Kubernetes
Submitted None
Reported by codermak

Vulnerability Details

Technical details and impact analysis

Improper Access Control - Generic
Report Submission Form ## Summary: Kubernetes docs has Spanish translation available. One of the page of Portuguese doc has an external reference to a github repository. The github account was not registered on github.com. So I was able to takeover the page and host the PoC ## Kubernetes Version: NA ## Component Version: NA ## Steps To Reproduce: 1. Go to https://kubernetes.io/pt-br/docs/concepts/cluster-administration/addons/ 2. Search for `Multus` 3. Click on `Multus` 4. You will be taken to this repository https://github.com/Intel-Corp/multus-cni and you will see takeover message there ## Supporting Material/References: - https://github.com/Intel-Corp/multus-cni - https://kubernetes.io/pt-br/docs/concepts/cluster-administration/addons/ {F1511425} ## Impact As an attacker, I can host malicious content on the github repository. I can also, host malicious sdk or softwares, which user will think is part of the deployment docs as its referreded in kubernetes.io, this can lead to RCE for users who are referring to this doc

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic