Open Redirect Affecting github.com/kubernetes/kubernetes/cmd/kube-apiserver/app package, versions <1.22.14 >=1.23.0 <1.23.11 >=1.24.0 <1.24.5 >=1.25.0 <1.25.1
Snyk CVSS
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Changed
Threat Intelligence
EPSS
0.07% (28th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMKUBERNETESKUBERNETESCMDKUBEAPISERVERAPP-3027030
- published 19 Sep 2022
- disclosed 16 Sep 2022
- credit Nicolas Joly, Weinong Wang
Introduced: 16 Sep 2022
CVE-2022-3172 Open this link in a new tabHow to fix?
Upgrade github.com/kubernetes/kubernetes/cmd/kube-apiserver/app
to version 1.22.14, 1.23.11, 1.24.5, 1.25.1 or higher.
Overview
Affected versions of this package are vulnerable to Open Redirect by allowing an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.