Vulnerabilities > CVE-2022-3172 - Server-Side Request Forgery (SSRF) vulnerability in Kubernetes Apiserver

047910
CVSS 8.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
LOW
Availability impact
NONE
network
low complexity
kubernetes
CWE-918

Summary

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.

Common Weakness Enumeration (CWE)