Open Redirect Affecting github.com/kubernetes/kubernetes/cmd/kube-apiserver/app package, versions <1.22.14 >=1.23.0 <1.23.11 >=1.24.0 <1.24.5 >=1.25.0 <1.25.1


0.0
medium

Snyk CVSS

    Attack Complexity High
    Privileges Required High
    User Interaction Required
    Scope Changed

    Threat Intelligence

    EPSS 0.07% (28th percentile)
Expand this section
NVD
8.2 high
Expand this section
Red Hat
5.1 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-GOLANG-GITHUBCOMKUBERNETESKUBERNETESCMDKUBEAPISERVERAPP-3027030
  • published 19 Sep 2022
  • disclosed 16 Sep 2022
  • credit Nicolas Joly, Weinong Wang

How to fix?

Upgrade github.com/kubernetes/kubernetes/cmd/kube-apiserver/app to version 1.22.14, 1.23.11, 1.24.5, 1.25.1 or higher.

Overview

Affected versions of this package are vulnerable to Open Redirect by allowing an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.