PT-2022-13208 · Mirantis · Mirantis Container Cloud Lens Extension
Mirantis Psirt
·
Published
2022-02-04
·
Updated
2022-02-09
·
CVE-2022-0484
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mirantis Container Cloud Lens Extension versions prior to v3.1.1
Description
The issue is caused by a lack of validation of URLs, which allows an attacker to induce the victim to add a new cluster via a malicious URL. This could lead to the opening of external programs other than the default browser to perform sign on to a new cluster. An attacker could host a webserver serving a malicious Mirantis Container Cloud configuration file.
Recommendations
For versions prior to v3.1.1, update to version v3.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the addition of new clusters via URLs to minimize the risk of exploitation. Avoid using untrusted URLs when adding new clusters until the issue is resolved.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mirantis Container Cloud Lens Extension