Back

MEDIUM

openshift/router: route hijacking attack via crafted HAProxy configuration file

Published Sep 1, 2022

Description

In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary application within the cluster, including one under attacker control.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Sep 1, 2022
Updated Aug 3, 2024
Reserved May 11, 2022

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date May 13, 2022
Bugzilla 2076211

ENISA EUVD

Assigner redhat
Published Sep 1, 2022
Updated Aug 3, 2024

GitHub

No data