CVE-2022-3172 MEDIUM

CVE-2022-3172: Kubernetes - API server - Aggregated API server can cause clients to be redirected (SSRF)

Vendor Kubernetes
Product kube-apiserver
Weakness CWE-918 · SSRF
Published November 3, 2023
Last update February 13, 2025

CVSS base score

5.1/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.

Key dates

02Disclosure timeline

November 3, 2023 CVE published
February 13, 2025 Record updated

Related vulnerabilities

04Related CVE