← Retour aux CVEs
CVE-2022-3294
MEDIUM6.6
Description
Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server's private network.
Details CVE
Score CVSS v3.16.6
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteHIGH
Privileges requisHIGH
Interaction utilisateurNONE
Publie3/1/2023
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
kubernetes:kubernetes
Faiblesses (CWE)
CWE-20
References
https://github.com/kubernetes/kubernetes/issues/113757(jordan@liggitt.net)
https://groups.google.com/g/kubernetes-security-announce/c/VyPOxF7CIbA(jordan@liggitt.net)
https://security.netapp.com/advisory/ntap-20230505-0007/(jordan@liggitt.net)
https://github.com/kubernetes/kubernetes/issues/113757(af854a3a-2127-422b-91ae-364da2661108)
https://groups.google.com/g/kubernetes-security-announce/c/VyPOxF7CIbA(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20230505-0007/(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.