CVE-2022-3172
published 2023-11-03CVE-2022-3172: A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client…
PriorityP345high8.2CVSS 3.1
AVNACLPRNUIRSCCHILAN
EPSS
2.46%
82.7th percentile
A security issue was discovered in kube-apiserver that allows an
aggregated API server to redirect client traffic to any URL. This could
lead to the client performing unexpected actions as well as forwarding
the client's API server credentials to third parties.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kubernetes | < kubernetes 1.20.5+really1.20.2-1 (bookworm) | kubernetes 1.20.5+really1.20.2-1 (bookworm) |
| kubernetes | apiserver | <= 1.21.14 | — |
| kubernetes | apiserver | — | — |
| kubernetes | apiserver | >= 1.22.0 < 1.22.14 | 1.22.14 |
| kubernetes | apiserver | >= 1.23.0 < 1.23.11 | 1.23.11 |
| kubernetes | apiserver | >= 1.24.0 < 1.24.5 | 1.24.5 |
| kubernetes | kube-apiserver | <= v1.21.14 | — |
| kubernetes | kube-apiserver | — | — |
| kubernetes | kube-apiserver | v1.22.0 – v1.22.13 | — |
| kubernetes | kube-apiserver | v1.23.0 – v1.23.10 | — |
| kubernetes | kube-apiserver | v1.24.0 – v1.24.4 | — |
| kubernetes | kubernetes | >= 0 < 1.20.5+really1.20.2-1 | 1.20.5+really1.20.2-1 |
| kubernetes | kubernetes | >= 0 < 1.20.5+really1.20.2-1 | 1.20.5+really1.20.2-1 |
| kubernetes | kubernetes | >= 0 < 1.20.5+really1.20.2-1 | 1.20.5+really1.20.2-1 |
| kubernetes | kubernetes | >= 0 < 1.20.5+really1.20.2-1 | 1.20.5+really1.20.2-1 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
osv8.2HIGH
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kube-apiserver: Aggregated API server can cause clients to be redirected (SSRF)
vendor_redhat·2022-09-16·CVSS 5.1
CVE-2022-3172 [MEDIUM] CWE-918 kube-apiserver: Aggregated API server can cause clients to be redirected (SSRF)
kube-apiserver: Aggregated API server can cause clients to be redirected (SSRF)
A security issue was discovered in kube-apiserver that allows an
aggregated API server to redirect client traffic to any URL. This could
lead to the client performing unexpected actions as well as forwarding
the client's API server credentials to third parties.
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This issue leads to the client performing unexpected actions and forwarding the client's API server credentials to third parties.
Package: atomic-openshift (Red Hat OpenShift Container Platform 3.11) - Out of support scope
Package: openshift4/ose-openshift-apiserver-rhel8 (Red Hat OpenShift Container Platform 4) - Not affected
Debian
CVE-2022-3172: kubernetes - A security issue was discovered in kube-apiserver that allows an aggregated API...
vendor_debian·2022·CVSS 5.1
CVE-2022-3172 [MEDIUM] CVE-2022-3172: kubernetes - A security issue was discovered in kube-apiserver that allows an aggregated API...
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.
Scope: local
bookworm: resolved (fixed in 1.20.5+really1.20.2-1)
bullseye: resolved (fixed in 1.20.5+really1.20.2-1)
forky: resolved (fixed in 1.20.5+really1.20.2-1)
sid: resolved (fixed in 1.20.5+really1.20.2-1)
trixie: resolved (fixed in 1.20.5+really1.20.2-1)
OSV
CVE-2022-3172: A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL
osv·2023-11-03·CVSS 8.2
CVE-2022-3172 [HIGH] CVE-2022-3172: A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.
No detection rules found.
No public exploits indexed.
https://github.com/kubernetes/kubernetes/issues/112513https://groups.google.com/g/kubernetes-security-announce/c/_aLzYMpPRakhttps://security.netapp.com/advisory/ntap-20231221-0005/https://github.com/kubernetes/kubernetes/issues/112513https://groups.google.com/g/kubernetes-security-announce/c/_aLzYMpPRakhttps://security.netapp.com/advisory/ntap-20231221-0005/
2023-11-03
Published