Lucene search

K
osvGoogleOSV:CVE-2022-3172
HistoryNov 03, 2023 - 8:15 p.m.

CVE-2022-3172

2023-11-0320:15:08
Google
osv.dev
10
cve-2022-3172
aggregated api server
client traffic redirection
unexpected actions
api server credentials

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.3%

A security issue was discovered in kube-apiserver that allows an
aggregated API server to redirect client traffic to any URL. This could
lead to the client performing unexpected actions as well as forwarding
the clientโ€™s API server credentials to third parties.

8.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

7.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.3%