Skip to content

Improper Access Control in kctf

High
sroettger published GHSA-4g2v-6qc6-6jv5 Jun 13, 2022

Package

kctf (kctf)

Affected versions

< 1.6.0

Patched versions

1.6.0

Description

Impact

The kctf cluster set-src-ip-ranges was broken and allowed traffic from any IP.

Patches

The problem has been patched in v1.6.0

Workarounds

If you want to test challenges privately, you can mark them as public: false and use kctf chal debug port-forward to connect.

For more information

In case of questions or suggestions, you can reach us in #kctf.

Severity

High

CVE ID

CVE-2022-31055

Weaknesses