CVE-2022-3162

MEDIUM6.5EPSS 1.0%

Kubernetes vulnerable to path traversal

發布日:2023/3/1修改日:2024/8/20
也稱為:GHSA-2394-5535-8j88DEBIAN-CVE-2022-3162GO-2023-1628

描述

Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are true: 1. There are 2+ CustomResourceDefinitions sharing the same API group 2. Users have cluster-wide list or watch authorization on one of those custom resources. 3. The same users are not authorized to read another custom resource in the same API group.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

參考連結(7)