Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2385

Опубликовано: 11 июл. 2022
Источник: redhat
CVSS3: 8.1

Описание

A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.

A flaw was found in aws-iam-authenticator. This issue occurs when an allow-listed IAM identity may be able to modify their username and escalate privileges.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-hypershift-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2107036aws-iam-authenticator: AccessKeyID validation bypass

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
больше 3 лет назад

A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.

suse-cvrf
больше 3 лет назад

Security update for aws-iam-authenticator

CVSS3: 8.1
github
больше 3 лет назад

aws-iam-authenticator allow-listed IAM identity may be able to modify their username, escalate privileges before v0.5.9

8.1 High

CVSS3