PT-2022-13208 · Mirantis · Mirantis Container Cloud Lens Extension

Mirantis Psirt

·

Published

2022-02-04

·

Updated

2022-02-09

·

CVE-2022-0484

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mirantis Container Cloud Lens Extension versions prior to v3.1.1
Description The issue is caused by a lack of validation of URLs, which allows an attacker to induce the victim to add a new cluster via a malicious URL. This could lead to the opening of external programs other than the default browser to perform sign on to a new cluster. An attacker could host a webserver serving a malicious Mirantis Container Cloud configuration file.
Recommendations For versions prior to v3.1.1, update to version v3.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the addition of new clusters via URLs to minimize the risk of exploitation. Avoid using untrusted URLs when adding new clusters until the issue is resolved.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0484

Affected Products

Mirantis Container Cloud Lens Extension