CVE-2022-3172 Vulnerability Details

  /     /     /  

CVE-2022-3172 Metadata Quick Info

CVE Published: 03/11/2023 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: kubernetes | Vendor: Kubernetes | Product: kube-apiserver
Status : PUBLISHED

CVE-2022-3172 Description

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client\'s API server credentials to third parties.

Metrics

CVSS Version: 3.1 | Base Score: 5.1 MEDIUM
Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* HIGH
    User Interaction (UI)* REQUIRED
    Scope (S)* CHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* LOW
    Integrity Impact (I)* LOW
    Availability Impact (A)* LOW

Weakness Enumeration (CWE)

CWE-ID: CWE-918
CWE Name: CWE-918 Server-Side Request Forgery (SSRF)
Source: Kubernetes

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-560
CAPEC Description: CAPEC-560 Use of Known Domain Credentials


Source: NVD (National Vulnerability Database).