Database/Container, Kubernetes & orchestration
Kubernetes (kube-apiserver): Node address not verified when proxying
CVE-2022-3294Container, Kubernetes & orchestrationcurated
Impact
Node address not verified when proxying; a user who can modify Node objects reaches control-plane-only endpoints
Who can reach it
Cluster user able to patch Node objects
What to do
Rolling control-plane upgrade; restrict Node patch RBAC
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.