Site icon API Security Blog

KubePi may leak password hash of any user

### Summary
https://kube.pi/kubepi/api/v1/users/search?pageNum=1&&pageSize=10 leak password of any user (including admin). This leads to password crack attack

### PoC
https://drive.google.com/file/d/1ksdawJ1vShRJyT3wAgpqVmz-Ls6hMA7M/preview

### Impact
– Leaking confidential information.
– Can lead to password cracking attacksRead More

Exit mobile version