{
  "threat_severity" : "Moderate",
  "public_date" : "2022-09-16T00:00:00Z",
  "bugzilla" : {
    "description" : "kube-apiserver: Aggregated API server can cause clients to be redirected (SSRF)",
    "id" : "2127804",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2127804"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.1",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-918",
  "details" : [ "A security issue was discovered in kube-apiserver that allows an \naggregated API server to redirect client traffic to any URL.  This could\nlead to the client performing unexpected actions as well as forwarding \nthe client's API server credentials to third parties.", "A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This issue leads to the client performing unexpected actions and forwarding the client's API server credentials to third parties." ],
  "affected_release" : [ {
    "product_name" : "Red Hat OpenShift Container Platform 4.10",
    "release_date" : "2023-04-12T00:00:00Z",
    "advisory" : "RHSA-2023:1655",
    "cpe" : "cpe:/a:redhat:openshift:4.10::el7",
    "package" : "openshift-0:4.10.0-202303221742.p0.g16bcd69.assembly.stream.el7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.11",
    "release_date" : "2022-11-02T00:00:00Z",
    "advisory" : "RHBA-2022:7200",
    "cpe" : "cpe:/a:redhat:openshift:4.11::el8",
    "package" : "openshift-0:4.11.0-202210122157.p0.g5157800.assembly.stream.el8"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.12",
    "release_date" : "2023-01-17T00:00:00Z",
    "advisory" : "RHSA-2022:7398",
    "cpe" : "cpe:/a:redhat:openshift:4.12::el8",
    "package" : "openshift-0:4.12.0-202301042257.p0.g77bec7a.assembly.stream.el8"
  }, {
    "product_name" : "RHODF-4.12-RHEL-8",
    "release_date" : "2023-06-14T00:00:00Z",
    "advisory" : "RHSA-2023:3609",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.12::el8",
    "package" : "odf4/ocs-rhel8-operator:v4.12.4-2"
  }, {
    "product_name" : "RHODF-4.12-RHEL-8",
    "release_date" : "2023-06-14T00:00:00Z",
    "advisory" : "RHSA-2023:3609",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4.12::el8",
    "package" : "odf4/odf-rhel8-operator:v4.12.4-2"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenShift Container Platform 3.11",
    "fix_state" : "Out of support scope",
    "package_name" : "atomic-openshift",
    "cpe" : "cpe:/a:redhat:openshift:3.11"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Not affected",
    "package_name" : "openshift4/ose-openshift-apiserver-rhel8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "openshift4/ose-tests",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat Openshift Container Storage 4",
    "fix_state" : "Out of support scope",
    "package_name" : "ocs4/ocs-rhel8-operator",
    "cpe" : "cpe:/a:redhat:openshift_container_storage:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2022-3172\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-3172\nhttps://github.com/kubernetes/kubernetes/issues/112513" ],
  "name" : "CVE-2022-3172",
  "csaw" : false
}