CVE-2022-3172
Publication date 3 November 2023
Last updated 4 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| kubernetes | ||
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Ignored end of standard support | |
| 14.04 LTS trusty | Ignored end of standard support |
Notes
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.1 · Medium
Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L