CVE-2022-3962

MEDIUM4.3EPSS 0.11%

Kiali content spoofing vulnerability

發布日:2023/9/23修改日:2026/2/4
也稱為:GHSA-6f4m-j56w-55c3CGA-mxhp-8gqc-3jj3GO-2023-2075

描述

A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM4.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

參考連結(8)