Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3962

Опубликовано: 22 нояб. 2022
Источник: redhat
CVSS3: 4.3

Описание

A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2.1openshift-service-mesh/kiali-rhel8Will not fix
Red Hat OpenShift Service Mesh 2.3 for RHEL 8openshift-service-mesh/kiali-rhel8FixedRHSA-2023:054230.01.2023

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-74
https://bugzilla.redhat.com/show_bug.cgi?id=2148661kiali: error message spoofing in kiali UI

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
больше 2 лет назад

A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.

CVSS3: 4.3
github
больше 2 лет назад

Kiali content spoofing vulnerability

4.3 Medium

CVSS3