CVE-2022-3248
published 2023-10-05CVE-2022-3248: A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.40%
32.7th percentile
A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | advanced_cluster_management_for_kubernetes | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kubernetes: OpenShift API admission checks does not enforce "custom-host" permissions
vendor_redhat·2023-10-05·CVSS 4.4
CVE-2022-3248 [MEDIUM] CWE-863 kubernetes: OpenShift API admission checks does not enforce "custom-host" permissions
kubernetes: OpenShift API admission checks does not enforce "custom-host" permissions
A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.
A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.
Package: rhacm2/agent-service-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Affected
Package: kubernetes (Red Hat Ansible Automation Platform 1.2) - Not affected
Package: kubernetes (Red Hat Ansible Tower 3) - Not affected
Package: atomic-openshift (Red Hat OpenShift Container Platform 3.11) - Out of
GHSA
GHSA-4rc4-8xqr-5g82: A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions
ghsa_unreviewed·2023-10-05
CVE-2022-3248 [HIGH] CWE-863 GHSA-4rc4-8xqr-5g82: A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions
A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.
No detection rules found.
No public exploits indexed.
2023-10-05
Published