CVE-2022-4039
published 2023-09-22CVE-2022-4039: A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.79%
52.4th percentile
A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform_for_ibm_z | — | — |
| redhat | openshift_container_platform_for_ibm_z | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rhsso-container-image: unsecured management interface exposed to adjecent network
vendor_redhat·2023-02-28·CVSS 8.0
CVE-2022-4039 [HIGH] CWE-276 rhsso-container-image: unsecured management interface exposed to adjecent network
rhsso-container-image: unsecured management interface exposed to adjecent network
A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration.
A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration.
Package: rhsso-container-image (Red Hat Single Sign-On 7) - Affected
GHSA
GHSA-7g6j-5xq2-wgqv: A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled
ghsa_unreviewed·2023-09-22
CVE-2022-4039 [CRITICAL] CWE-276 GHSA-7g6j-5xq2-wgqv: A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled
A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration.
No detection rules found.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:1047https://access.redhat.com/security/cve/CVE-2022-4039https://bugzilla.redhat.com/show_bug.cgi?id=2143416https://access.redhat.com/errata/RHSA-2023:1047https://access.redhat.com/security/cve/CVE-2022-4039https://bugzilla.redhat.com/show_bug.cgi?id=2143416
2023-09-22
Published