mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-08-04 08:44:25 +00:00
156 lines
6.7 KiB
JSON
156 lines
6.7 KiB
JSON
{
|
|
"data_version": "4.0",
|
|
"data_type": "CVE",
|
|
"data_format": "MITRE",
|
|
"CVE_data_meta": {
|
|
"ID": "CVE-2022-3172",
|
|
"ASSIGNER": "security@kubernetes.io",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "A security issue was discovered in kube-apiserver that allows an \naggregated API server to redirect client traffic to any URL. This could\n lead to the client performing unexpected actions as well as forwarding \nthe client's API server credentials to third parties.\n"
|
|
}
|
|
]
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "CWE-918 Server-Side Request Forgery (SSRF)",
|
|
"cweId": "CWE-918"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"vendor_name": "Kubernetes",
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "kube-apiserver",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "not down converted",
|
|
"x_cve_json_5_version_data": {
|
|
"versions": [
|
|
{
|
|
"status": "affected",
|
|
"version": "v1.25.0"
|
|
},
|
|
{
|
|
"lessThanOrEqual": "v1.24.4",
|
|
"status": "affected",
|
|
"version": "v1.24.0",
|
|
"versionType": "semver"
|
|
},
|
|
{
|
|
"lessThanOrEqual": "v1.23.10",
|
|
"status": "affected",
|
|
"version": "v1.23.0",
|
|
"versionType": "semver"
|
|
},
|
|
{
|
|
"lessThanOrEqual": "v1.22.13",
|
|
"status": "affected",
|
|
"version": "v1.22.0",
|
|
"versionType": "semver"
|
|
},
|
|
{
|
|
"status": "unaffected",
|
|
"version": "v1.25.1"
|
|
},
|
|
{
|
|
"status": "unaffected",
|
|
"version": "v1.24.5"
|
|
},
|
|
{
|
|
"status": "unaffected",
|
|
"version": "v1.23.11"
|
|
},
|
|
{
|
|
"status": "unaffected",
|
|
"version": "v1.22.14"
|
|
},
|
|
{
|
|
"lessThanOrEqual": "v1.21.14",
|
|
"status": "affected",
|
|
"version": "0",
|
|
"versionType": "semver"
|
|
}
|
|
],
|
|
"defaultStatus": "unaffected"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"url": "https://github.com/kubernetes/kubernetes/issues/112513",
|
|
"refsource": "MISC",
|
|
"name": "https://github.com/kubernetes/kubernetes/issues/112513"
|
|
},
|
|
{
|
|
"url": "https://groups.google.com/g/kubernetes-security-announce/c/_aLzYMpPRak",
|
|
"refsource": "MISC",
|
|
"name": "https://groups.google.com/g/kubernetes-security-announce/c/_aLzYMpPRak"
|
|
},
|
|
{
|
|
"url": "https://security.netapp.com/advisory/ntap-20231221-0005/",
|
|
"refsource": "MISC",
|
|
"name": "https://security.netapp.com/advisory/ntap-20231221-0005/"
|
|
}
|
|
]
|
|
},
|
|
"generator": {
|
|
"engine": "Vulnogram 0.1.0-dev"
|
|
},
|
|
"source": {
|
|
"discovery": "EXTERNAL"
|
|
},
|
|
"credits": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Nicolas Joly"
|
|
},
|
|
{
|
|
"lang": "en",
|
|
"value": "Weinong Wang"
|
|
}
|
|
],
|
|
"impact": {
|
|
"cvss": [
|
|
{
|
|
"attackComplexity": "HIGH",
|
|
"attackVector": "NETWORK",
|
|
"availabilityImpact": "LOW",
|
|
"baseScore": 5.1,
|
|
"baseSeverity": "MEDIUM",
|
|
"confidentialityImpact": "LOW",
|
|
"integrityImpact": "LOW",
|
|
"privilegesRequired": "HIGH",
|
|
"scope": "CHANGED",
|
|
"userInteraction": "REQUIRED",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L",
|
|
"version": "3.1"
|
|
}
|
|
]
|
|
}
|
|
} |