PT-2022-5431 · Unknown+3 · Kubernetes+2
Richard Turnbull
·
Published
2022-11-10
·
Updated
2025-08-08
·
CVE-2022-3162
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Kubernetes (affected versions not specified)
Description
The issue is related to insufficient access control in Kubernetes, allowing users authorized to list or watch one type of namespaced custom resource cluster-wide to read custom resources of a different type in the same API group without authorization. This affects clusters with 2+ CustomResourceDefinitions sharing the same API group, where users have cluster-wide list or watch authorization on one custom resource but not on another in the same API group.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Path traversal
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Kubernetes
Suse