A security issue was discovered in kube-apiserver that allows an
aggregated API server to redirect client traffic to any URL. This could
lead to the client performing unexpected actions as well as forwarding
the client's API server credentials to third parties.
References
Link | Resource |
---|---|
https://github.com/kubernetes/kubernetes/issues/112513 | Issue Tracking Vendor Advisory |
https://groups.google.com/g/kubernetes-security-announce/c/_aLzYMpPRak | Mailing List |
https://security.netapp.com/advisory/ntap-20231221-0005/ | |
https://github.com/kubernetes/kubernetes/issues/112513 | Issue Tracking Vendor Advisory |
https://groups.google.com/g/kubernetes-security-announce/c/_aLzYMpPRak | Mailing List |
https://security.netapp.com/advisory/ntap-20231221-0005/ |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/kubernetes/kubernetes/issues/112513 - Issue Tracking, Vendor Advisory | |
References | () https://groups.google.com/g/kubernetes-security-announce/c/_aLzYMpPRak - Mailing List | |
References | () https://security.netapp.com/advisory/ntap-20231221-0005/ - | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.1 |
21 Dec 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
14 Nov 2023, 16:26
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-918 | |
First Time |
Kubernetes
Kubernetes apiserver |
|
CPE | cpe:2.3:a:kubernetes:apiserver:1.25.0:*:*:*:*:*:*:* cpe:2.3:a:kubernetes:apiserver:*:*:*:*:*:*:*:* |
|
References | (MISC) https://github.com/kubernetes/kubernetes/issues/112513 - Issue Tracking, Vendor Advisory | |
References | (MISC) https://groups.google.com/g/kubernetes-security-announce/c/_aLzYMpPRak - Mailing List | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.2 |
03 Nov 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-03 20:15
Updated : 2024-11-21 07:18
NVD link : CVE-2022-3172
Mitre link : CVE-2022-3172
CVE.ORG link : CVE-2022-3172
JSON object : View
Products Affected
kubernetes
- apiserver
CWE
CWE-918
Server-Side Request Forgery (SSRF)