Open Redirect Affecting k8s.io/kubernetes/cmd/kube-apiserver/app package, versions <1.22.14 >=1.23.0 <1.23.11 >=1.24.0 <1.24.5 >=1.25.0 <1.25.1


0.0
low
  • Attack Complexity

    High

  • Privileges Required

    High

  • User Interaction

    Required

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • snyk-id

    SNYK-GOLANG-K8SIOKUBERNETESCMDKUBEAPISERVERAPP-3027031

  • published

    19 Sep 2022

  • disclosed

    16 Sep 2022

  • credit

    Nicolas Joly, Weinong Wang

How to fix?

Upgrade k8s.io/kubernetes/cmd/kube-apiserver/app to version 1.22.14, 1.23.11, 1.24.5, 1.25.1 or higher.

Overview

Affected versions of this package are vulnerable to Open Redirect by allowing an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.