PT-2022-5031 · Microsoft · Azure Stack Edge+1

Mo Khan

·

Published

2022-10-11

·

Updated

2025-01-02

·

CVE-2022-37968

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Azure Arc-enabled Kubernetes clusters (affected versions not specified) Azure Stack Edge (affected versions not specified)
Description The issue is related to access control flaws in the Azure Arc gateway and Azure Stack Edge, which could allow an unauthenticated user to elevate their privileges. This might potentially grant administrative control over the Kubernetes cluster. The vulnerability can be exploited remotely.
Recommendations For Azure Arc-enabled Kubernetes clusters, restrict access to the cluster connect feature until a patch is available. For Azure Stack Edge devices, consider disabling the deployment of Kubernetes workloads via Azure Arc as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2022-06248
CVE-2022-37968

Affected Products

Azure Arc-Enabled Kubernetes
Azure Stack Edge