Kubernetes - API server - Aggregated API server can cause clients to be redirected (SSRF)
Published Nov 3, 2023
8.2
HIGHCVSS 3.1
EPSS 2.46%
Description
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.
Affected products
-
Affected
- ≥ 0, ≤ v1.21.14
- ≥ v1.22.0, ≤ v1.22.13
- ≥ v1.23.0, ≤ v1.23.10
- ≥ v1.24.0, ≤ v1.24.4
- v1.25.0
Unaffected
- v1.22.14
- v1.23.11
- v1.24.5
- v1.25.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Kubernetes | Kube-Apiserver | unaffected | Affected
Unaffected
|
- ≤ 1.21.14
- ≥ 1.22.0 · < 1.22.14
- ≥ 1.23.0 · < 1.23.11
- ≥ 1.24.0 · < 1.24.5
- 1.25.0
No data.
RHODF-4.12-RHEL-8
odf4/ocs-rhel8-operator:v4.12.4-2
Fixed · RHSA-2023:3609
RHODF-4.12-RHEL-8
odf4/odf-rhel8-operator:v4.12.4-2
Fixed · RHSA-2023:3609
Red Hat OpenShift Container Platform 4.10
openshift-0:4.10.0-202303221742.p0.g16bcd69.assembly.stream.el7
Fixed · RHSA-2023:1655
Red Hat OpenShift Container Platform 4.11
openshift-0:4.11.0-202210122157.p0.g5157800.assembly.stream.el8
Fixed · RHBA-2022:7200
Red Hat OpenShift Container Platform 4.12
openshift-0:4.12.0-202301042257.p0.g77bec7a.assembly.stream.el8
Fixed · RHSA-2022:7398
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 4
openshift4/ose-openshift-apiserver-rhel8
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-tests
Will not fix
Red Hat Openshift Container Storage 4
ocs4/ocs-rhel8-operator
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| RHODF-4.12-RHEL-8 | odf4/ocs-rhel8-operator:v4.12.4-2 | Fixed | RHSA-2023:3609 |
| RHODF-4.12-RHEL-8 | odf4/odf-rhel8-operator:v4.12.4-2 | Fixed | RHSA-2023:3609 |
| Red Hat OpenShift Container Platform 4.10 | openshift-0:4.10.0-202303221742.p0.g16bcd69.assembly.stream.el7 | Fixed | RHSA-2023:1655 |
| Red Hat OpenShift Container Platform 4.11 | openshift-0:4.11.0-202210122157.p0.g5157800.assembly.stream.el8 | Fixed | RHBA-2022:7200 |
| Red Hat OpenShift Container Platform 4.12 | openshift-0:4.12.0-202301042257.p0.g77bec7a.assembly.stream.el8 | Fixed | RHSA-2022:7398 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-openshift-apiserver-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-tests | Will not fix | n/a |
| Red Hat Openshift Container Storage 4 | ocs4/ocs-rhel8-operator | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-3172 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2127804 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42593 Advisory
- https://github.com/kubernetes/kubernetes/issues/112513 issue-trackingIssue TrackingVendor Advisory
- https://groups.google.com/g/kubernetes-security-announce/c/_aLzYMpPRak mailing-listMailing List
- https://nvd.nist.gov/vuln/detail/CVE-2022-3172
- https://security.netapp.com/advisory/ntap-20231221-0005/
- https://www.cve.org/CVERecord?id=CVE-2022-3172
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3172 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2127804 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-42593 | Advisory | |
| https://github.com/kubernetes/kubernetes/issues/112513 | issue-trackingIssue TrackingVendor Advisory | |
| https://groups.google.com/g/kubernetes-security-announce/c/_aLzYMpPRak | mailing-listMailing List | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3172 | ||
| https://security.netapp.com/advisory/ntap-20231221-0005/ | ||
| https://www.cve.org/CVERecord?id=CVE-2022-3172 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data