You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This issue leads to the client performing unexpected actions and forwarding the client's API server credentials to third parties
CVE-2022-3172 - Medium Severity Vulnerability
Vulnerable Library - k8s.io/apimachinery-v0.24.4
null
Library home page: https://proxy.golang.org/k8s.io/apimachinery/@v/v0.24.4.zip
Dependency Hierarchy:
Found in HEAD commit: f3e645589d16bc84a521e81b24dc90fe098643ad
Found in base branch: main
Vulnerability Details
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This issue leads to the client performing unexpected actions and forwarding the client's API server credentials to third parties
Publish Date: 2022-09-10
URL: CVE-2022-3172
CVSS 3 Score Details (5.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://bugzilla.redhat.com/show_bug.cgi?id=2127804
Release Date: 2022-09-10
Fix Resolution: v1.22.14,v1.23.11,v1.24.5,v1.25.1
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: