Описание
A security issue was discovered in kube-apiserver that allows an
aggregated API server to redirect client traffic to any URL. This could
lead to the client performing unexpected actions as well as forwarding
the client's API server credentials to third parties.
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This issue leads to the client performing unexpected actions and forwarding the client's API server credentials to third parties.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Out of support scope | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-openshift-apiserver-rhel9 | Not affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-tests | Will not fix | ||
Red Hat Openshift Container Storage 4 | ocs4/ocs-rhel8-operator | Out of support scope | ||
Red Hat OpenShift Container Platform 4.10 | openshift | Fixed | RHSA-2023:1655 | 12.04.2023 |
Red Hat OpenShift Container Platform 4.11 | openshift | Fixed | RHBA-2022:7200 | 02.11.2022 |
Red Hat OpenShift Container Platform 4.12 | openshift | Fixed | RHSA-2022:7398 | 17.01.2023 |
RHODF-4.12-RHEL-8 | odf4/ocs-rhel8-operator | Fixed | RHSA-2023:3609 | 14.06.2023 |
RHODF-4.12-RHEL-8 | odf4/odf-rhel8-operator | Fixed | RHSA-2023:3609 | 14.06.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.1 Medium
CVSS3
Связанные уязвимости
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.
A security issue was discovered in kube-apiserver that allows an aggr ...
EPSS
5.1 Medium
CVSS3