{"schema_version":"1.9.0","id":"CVE-2024-46528","published":"2024-10-14T00:00:00Z","modified":"2026-08-12T03:51:13.289176711Z","aliases":["GHSA-p26r-gfgc-c47h","GO-2024-3248"],"related":["openSUSE-SU-2024:14599-1"],"details":"An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through 3.5.0 allows low-privileged authenticated attackers to access sensitive resources without proper authorization checks.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kubesphere/kubesphere","events":[{"introduced":"0"},{"fixed":"3ef3a6bc98b790480577e87fbc75bee5b3438862"},{"fixed":"3e0493a1c5e1c4413a7b77e8b408d428220ed929"}],"database_specific":{"extracted_events":[{"introduced":"4.x"},{"fixed":"4.1.3"},{"introduced":"3.x"},{"fixed":"3.4.1"}],"source":"DESCRIPTION"}}],"versions":["v4.1.3-rc.0","helm-chart-1.1.3","v4.1.2","helm-chart-1.1.2","v4.1.1","v3.4.0","v3.4.0-rc.0","v3.3.0-rc.3","v3.3.0","v3.3.0-rc.2","v3.3.0-rc.1","v3.3.0-rc.0","v3.3.0-alpha.1","v3.3.0-alpha.0","v3.2.0","v3.2.0-rc.1","v3.2.0-alpha.1","v3.2.0-alpha.0","v3.1.0","v3.1.0-alpha.0","v3.0.0","v2.1.0","advanced-2.0.2","advanced-2.0.0","advanced-1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-46528.json"}}],"references":[{"type":"WEB","url":"https://kubesphere.io/"},{"type":"WEB","url":"https://okankurtulus.com.tr/2024/09/09/idor-vulnerability-in-kubesphere/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/46xxx/CVE-2024-46528.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-46528"},{"type":"ADVISORY","url":"https://www.kubesphere.io/news/kubesphere-cve-2024-46528/"},{"type":"REPORT","url":"https://github.com/kubesphere/kubesphere/issues/6227"}],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/46xxx/CVE-2024-46528.json","unresolved_ranges":[{"extracted_events":[{"introduced":"3.x"},{"fixed":"3.5.0"}],"source":"DESCRIPTION"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}