Junglewise Threat Intelligence

CVE-2023-46254: capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name

CVE-2023-46254 · Severity: low · CVSS 3.1 · Published 2023-11-07

Technologies: github.com/projectcapsule/capsule (Go). Vendors: Go.

Executive brief

capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name

Affected products

  • Go github.com/projectcapsule/capsule
  • Go github.com/projectcapsule/capsule-proxy

Related threats