CVE-2022-3172

Publication date 3 November 2023

Last updated 4 August 2025


Ubuntu priority

Cvss 3 Severity Score

5.1 · Medium

Score breakdown

Description

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.

Read the notes from the security team

Status

Package Ubuntu Release Status
kubernetes 25.04 plucky Not in release
24.10 oracular Ignored end of life, was needs-triage
24.04 LTS noble
Not affected
23.10 mantic Ignored end of life, was needs-triage
23.04 lunar Ignored end of life, was needs-triage
22.10 kinetic Ignored end of life, was needs-triage
22.04 LTS jammy
Not affected
20.04 LTS focal
Not affected
18.04 LTS bionic Not in release
16.04 LTS xenial Ignored end of standard support
14.04 LTS trusty Ignored end of standard support

Notes


leosilva

kubernates is in fact a kubernetes installer that calls snap, not the package it self.

Severity score breakdown

Parameter Value
Base score 5.1 · Medium
Attack vector Network
Attack complexity High
Privileges required High
User interaction Required
Scope Changed
Confidentiality Low
Integrity impact Low
Availability impact Low
Vector CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L