CVE-2022-1677

In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary application within the cluster, including one under attacker control.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2022-1677 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2076211 Issue Tracking Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.7:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.8:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.9:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.10:*:*:*:*:*:*:*

History

12 Feb 2023, 22:15

Type Values Removed Values Added
CWE NVD-CWE-noinfo CWE-400
References
  • {'url': 'https://access.redhat.com/errata/RHSA-2022:2281', 'name': 'https://access.redhat.com/errata/RHSA-2022:2281', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2022:2268', 'name': 'https://access.redhat.com/errata/RHSA-2022:2268', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHBA-2022:1690', 'name': 'https://access.redhat.com/errata/RHBA-2022:1690', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2022:2283', 'name': 'https://access.redhat.com/errata/RHSA-2022:2283', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2022:2264', 'name': 'https://access.redhat.com/errata/RHSA-2022:2264', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2022:2272', 'name': 'https://access.redhat.com/errata/RHSA-2022:2272', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 21:22

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/errata/RHSA-2022:2281 -
  • (MISC) https://access.redhat.com/errata/RHSA-2022:2268 -
  • (MISC) https://access.redhat.com/errata/RHBA-2022:1690 -
  • (MISC) https://access.redhat.com/errata/RHSA-2022:2283 -
  • (MISC) https://access.redhat.com/errata/RHSA-2022:2264 -
  • (MISC) https://access.redhat.com/errata/RHSA-2022:2272 -

08 Sep 2022, 16:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3
CPE cpe:2.3:a:redhat:openshift_container_platform:4.10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.8:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.7:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.9:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2076211 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2076211 - Issue Tracking, Patch, Vendor Advisory
References (MISC) https://access.redhat.com/security/cve/CVE-2022-1677 - (MISC) https://access.redhat.com/security/cve/CVE-2022-1677 - Vendor Advisory
First Time Redhat openshift Container Platform
Redhat
CWE NVD-CWE-noinfo

01 Sep 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-01 21:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-1677

Mitre link : CVE-2022-1677

CVE.ORG link : CVE-2022-1677


JSON object : View

Products Affected

redhat

  • openshift_container_platform
CWE
CWE-400

Uncontrolled Resource Consumption

NVD-CWE-noinfo