Lucene search

K
cvelistKubernetesCVELIST:CVE-2022-3172
HistoryNov 03, 2023 - 6:11 p.m.

CVE-2022-3172 Kubernetes - API server - Aggregated API server can cause clients to be redirected (SSRF)

2023-11-0318:11:53
CWE-918
kubernetes
www.cve.org
6
kubernetes
api server
ssrf
security issue
redirected
client traffic
credentials

CVSS3

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

28.1%

A security issue was discovered in kube-apiserver that allows an
aggregated API server to redirect client traffic to any URL. This could
lead to the client performing unexpected actions as well as forwarding
the clientโ€™s API server credentials to third parties.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "kube-apiserver",
    "repo": "https://github.com/kubernetes/kubernetes",
    "vendor": "Kubernetes",
    "versions": [
      {
        "status": "affected",
        "version": "v1.25.0"
      },
      {
        "lessThanOrEqual": "v1.24.4",
        "status": "affected",
        "version": "v1.24.0",
        "versionType": "semver"
      },
      {
        "lessThanOrEqual": "v1.23.10",
        "status": "affected",
        "version": "v1.23.0",
        "versionType": "semver"
      },
      {
        "lessThanOrEqual": "v1.22.13",
        "status": "affected",
        "version": "v1.22.0",
        "versionType": "semver"
      },
      {
        "status": "unaffected",
        "version": "v1.25.1"
      },
      {
        "status": "unaffected",
        "version": "v1.24.5"
      },
      {
        "status": "unaffected",
        "version": "v1.23.11"
      },
      {
        "status": "unaffected",
        "version": "v1.22.14"
      },
      {
        "lessThanOrEqual": "v1.21.14",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

28.1%