Node address isn't always verified when proxying
Published Mar 1, 2023
8.8
HIGHCVSS 3.1
EPSS 1.62%
Description
Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server's private network.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=v1.22.15
- Version unspecifiedStatusaffectedConstraints<=v1.23.13
- Version unspecifiedStatusaffectedConstraints<=v1.24.7
- Version unspecifiedStatusaffectedConstraints<=v1.25.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Kubernetes | n/a |
|
- < 1.22.16
- ≥ 1.23.0 · < 1.23.14
- ≥ 1.24.0 · < 1.24.8
- ≥ 1.25.0 · < 1.25.4
No data.
Red Hat OpenShift Container Platform 4.12
microshift-0:4.12.1-202301261525.p0.g3db9e81.assembly.4.12.1.el8
Fixed · RHBA-2023:0452
Red Hat OpenShift Container Platform 3.11
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 4
openshift
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-tests
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4.12 | microshift-0:4.12.1-202301261525.p0.g3db9e81.assembly.4.12.1.el8 | Fixed | RHBA-2023:0452 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-tests | Not affected | n/a |
github.com/kubernetes/kubernetes
Go
Introduced 1.25.0 Fixed 1.25.4github.com/kubernetes/kubernetes
Go
Introduced 1.24.0 Fixed 1.24.8github.com/kubernetes/kubernetes
Go
Introduced 1.23.0 Fixed 1.23.14github.com/kubernetes/kubernetes
Go
Introduced 1.22.0 Fixed 1.22.16k8s.io/kubernetes
Go
Introduced 1.22.0 Fixed 1.22.16k8s.io/kubernetes
Go
Introduced 1.23.0 Fixed 1.23.14k8s.io/kubernetes
Go
Introduced 1.24.0 Fixed 1.24.8k8s.io/kubernetes
Go
Introduced 1.25.0 Fixed 1.25.4
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/kubernetes/kubernetes | 1.25.0 | 1.25.4 |
| Go | github.com/kubernetes/kubernetes | 1.24.0 | 1.24.8 |
| Go | github.com/kubernetes/kubernetes | 1.23.0 | 1.23.14 |
| Go | github.com/kubernetes/kubernetes | 1.22.0 | 1.22.16 |
| Go | k8s.io/kubernetes | 1.22.0 | 1.22.16 |
| Go | k8s.io/kubernetes | 1.23.0 | 1.23.14 |
| Go | k8s.io/kubernetes | 1.24.0 | 1.24.8 |
| Go | k8s.io/kubernetes | 1.25.0 | 1.25.4 |
Remediation
Vendor solution
Configuring an egress proxy for egress to the cluster network can mitigate this vulnerability
Red Hat statement
Kubernetes clusters are only affected if an untrusted user can modify Node objects and send requests proxying through them. The "openshift" component of Red Hat OpenShift Container Platform 4 was fixed in RHBA-2023:0452 and as such is marked not affected.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-3294 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2136675 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1049 Advisory
- https://github.com/advisories/GHSA-jh36-q97c-9928 Advisory
- https://github.com/kubernetes/kubernetes/issues/113757 PatchVendor Advisory
- https://groups.google.com/g/kubernetes-security-announce/c/VyPOxF7CIbA Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3294
- https://security.netapp.com/advisory/ntap-20230505-0007/
- https://www.cve.org/CVERecord?id=CVE-2022-3294
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3294 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2136675 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1049 | Advisory | |
| https://github.com/advisories/GHSA-jh36-q97c-9928 | Advisory | |
| https://github.com/kubernetes/kubernetes/issues/113757 | PatchVendor Advisory | |
| https://groups.google.com/g/kubernetes-security-announce/c/VyPOxF7CIbA | Mailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3294 | ||
| https://security.netapp.com/advisory/ntap-20230505-0007/ | ||
| https://www.cve.org/CVERecord?id=CVE-2022-3294 |
Change history (0)
No recorded changes yet.