Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3962

Опубликовано: 22 нояб. 2022
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Service Mesh 2.1openshift-service-mesh/kiali-rhel8Will not fix
Red Hat OpenShift Service Mesh 2.3 for RHEL 8openshift-service-mesh/kiali-rhel8FixedRHSA-2023:054230.01.2023

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-74
https://bugzilla.redhat.com/show_bug.cgi?id=2148661kiali: error message spoofing in kiali UI

EPSS

Процентиль: 50%
0.00711
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
почти 3 года назад

A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.

CVSS3: 4.3
github
почти 3 года назад

Kiali content spoofing vulnerability

EPSS

Процентиль: 50%
0.00711
Низкий

4.3 Medium

CVSS3