PT-2022-20897 · Kubernetes+1 · Kube-Apiserver+2

Nicolas Joly

+2

·

Published

2022-09-16

·

Updated

2023-12-21

·

CVE-2022-3172

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions kube-apiserver (affected versions not specified)
Description A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1520
ALT-PU-2023-1529
CVE-2022-3172
OESA-2022-1979
RHSA-2022:7398
RHSA-2023:1655

Affected Products

Alt Linux
Kubernetes
Kube-Apiserver