8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Karmada Dashboard is a general-purpose, web-based control panel for Karmada which is a multi-cluster management project. Prior to version 0.2.0, there is an authentication bypass vulnerability in the Karmada Dashboard API. The backend API endpoints (e.g., /api/v1/secret, /api/v1/service) did not enforce authentication, allowing unauthenticated users to access sensitive cluster information such as Secrets and Services directly. Although the web UI required a valid JWT for access, the API itself remained exposed to direct requests without any authentication checks. Any user or entity with network access to the Karmada Dashboard service could exploit this vulnerability to retrieve sensitive data.
AI Analysis
Authentication bypass vulnerability in Karmada Dashboard API, allowing unauthenticated access to sensitive cluster information
Basic Information
ID
CVE-2025-62714
Source
GitHub_M
Published
Oct 24, 2025 at 15:41
Modified
Oct 24, 2025 at 17:29
Affected Product
Vendor
karmada-io
Product
dashboard
Version
< 0.2.0
Affected Versions
karmada-io dashboard < 0.2.0
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
karmada-io
Product
Karmada Dashboard
Version
< 0.2.0
References
- github.com /karmada-io/dashboard/security/advisories/GHSA-5qjg-9mjh-4r92
- github.com /karmada-io/dashboard/pull/271
- github.com /karmada-io/dashboard/pull/280
- github.com /karmada-io/dashboard/commit/8457b8bb87725e2371a638ca5a255fd2895c70f1
- github.com /karmada-io/dashboard/commit/d2d04909f25e96b4c20fa6b636c398bd1636ee06
- github.com /karmada-io/dashboard/releases/tag/v0.2.0