CVE-2022-4039

Severity
9.8CRITICAL
EPSS
0.1%
top 68.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 22

Description

A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages1 packages

Also affects: Openshift Container Platform 4.10, 4.9

🔴Vulnerability Details

2
GHSA
GHSA-7g6j-5xq2-wgqv: A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled2023-09-22
CVEList
Rhsso-container-image: unsecured management interface exposed to adjecent network2023-09-22

💥Exploits & PoCs

1
Exploit-DB
Zyxel NWA-1100-NH - Command Injection2022-04-19

📋Vendor Advisories

1
Red Hat
rhsso-container-image: unsecured management interface exposed to adjecent network2023-02-28