openshift/router: route hijacking attack via crafted HAProxy configuration file
Published Sep 1, 2022
6.3
MEDIUMCVSS 3.1
EPSS 0.58%
Description
In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary application within the cluster, including one under attacker control.
Affected products
- Vendor n/a Product Openshift Defaultunknown
Affected
- Openshift 3.11 and 4.6 onwards
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Openshift | unknown | Affected
|
- 3.11
- 4.6
- 4.7
- 4.8
- 4.9
- 4.10
No data.
Red Hat OpenShift Container Platform 3.11
openshift3/ose-haproxy-router:v3.11.705-1.g7a17a5d
Fixed · RHSA-2022:2281
Red Hat OpenShift Container Platform 4.10
openshift4/ose-haproxy-router:v4.10.0-202204291840.p0.g11109e4.assembly.stream
Fixed · RHBA-2022:1690
Red Hat OpenShift Container Platform 4.6
openshift4/ose-haproxy-router:v4.6.0-202205131546.p0.g7d2af02.assembly.stream
Fixed · RHSA-2022:2264
Red Hat OpenShift Container Platform 4.7
openshift4/ose-haproxy-router:v4.7.0-202205131637.p0.ge246a5f.assembly.stream
Fixed · RHSA-2022:2268
Red Hat OpenShift Container Platform 4.8
openshift4/ose-haproxy-router:v4.8.0-202205131628.p0.gd0d6380.assembly.stream
Fixed · RHSA-2022:2272
Red Hat OpenShift Container Platform 4.9
openshift4/ose-haproxy-router:v4.9.0-202205131707.p0.gfe7ea46.assembly.stream
Fixed · RHSA-2022:2283
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | openshift3/ose-haproxy-router:v3.11.705-1.g7a17a5d | Fixed | RHSA-2022:2281 |
| Red Hat OpenShift Container Platform 4.10 | openshift4/ose-haproxy-router:v4.10.0-202204291840.p0.g11109e4.assembly.stream | Fixed | RHBA-2022:1690 |
| Red Hat OpenShift Container Platform 4.6 | openshift4/ose-haproxy-router:v4.6.0-202205131546.p0.g7d2af02.assembly.stream | Fixed | RHSA-2022:2264 |
| Red Hat OpenShift Container Platform 4.7 | openshift4/ose-haproxy-router:v4.7.0-202205131637.p0.ge246a5f.assembly.stream | Fixed | RHSA-2022:2268 |
| Red Hat OpenShift Container Platform 4.8 | openshift4/ose-haproxy-router:v4.8.0-202205131628.p0.gd0d6380.assembly.stream | Fixed | RHSA-2022:2272 |
| Red Hat OpenShift Container Platform 4.9 | openshift4/ose-haproxy-router:v4.9.0-202205131707.p0.gfe7ea46.assembly.stream | Fixed | RHSA-2022:2283 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://access.redhat.com/security/cve/CVE-2022-1677 x_refsource_MISCVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2076211 x_refsource_MISCIssue TrackingPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24963 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1677
- https://www.cve.org/CVERecord?id=CVE-2022-1677
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-1677 | x_refsource_MISCVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2076211 | x_refsource_MISCIssue TrackingPatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-24963 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-1677 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-1677 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data