CVE-2022-3962
published 2023-09-23CVE-2022-3962: A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed…
PriorityP421medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.71%
49.5th percentile
A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | kiali_kiali | >= 0 < 1.57.4 | 1.57.4 |
| redhat | openshift_service_mesh | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Kiali content spoofing vulnerability in github.com/kiali/kiali
osv·2024-08-21
CVE-2022-3962 Kiali content spoofing vulnerability in github.com/kiali/kiali
Kiali content spoofing vulnerability in github.com/kiali/kiali
Kiali content spoofing vulnerability in github.com/kiali/kiali
GHSA
Kiali content spoofing vulnerability
ghsa·2023-09-23
CVE-2022-3962 [MEDIUM] CWE-74 Kiali content spoofing vulnerability
Kiali content spoofing vulnerability
A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.
OSV
Kiali content spoofing vulnerability
osv·2023-09-23
CVE-2022-3962 [MEDIUM] Kiali content spoofing vulnerability
Kiali content spoofing vulnerability
A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.
Red Hat
kiali: error message spoofing in kiali UI
vendor_redhat·2022-11-22·CVSS 4.3
CVE-2022-3962 [MEDIUM] CWE-74 kiali: error message spoofing in kiali UI
kiali: error message spoofing in kiali UI
A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.
A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.
Package: openshift-service-mesh/kiali-rhel8 (OpenShift Service Mesh 2.1) - Will not fix
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:0542https://access.redhat.com/security/cve/CVE-2022-3962https://bugzilla.redhat.com/show_bug.cgi?id=2148661https://access.redhat.com/errata/RHSA-2023:0542https://access.redhat.com/security/cve/CVE-2022-3962https://bugzilla.redhat.com/show_bug.cgi?id=2148661
2023-09-23
Published