FlawAtlas
Search the atlas
CVE-2022-3162 Moderate

Kubernetes vulnerable to path traversal in k8s.io/kubernetes

Kubernetes vulnerable to path traversal in k8s.io/kubernetes

Exploit probability 1.2%
Published August 20, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

207 explicit affected versions

Go k8s.io/kubernetes
Go github.com/kubernetes/kubernetes

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2022-3162

Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are true: 1. There are 2+ CustomResourceDefinitions sharing the same API group 2. Users have cluster-wide list or watch authorization on one of those custom resources. 3. The same users are not authorized to read another custom resource in the same API group.

View original source
Open Source Vulnerabilities GHSA-2394-5535-8j88

Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different type in the same API group without authorization. Clusters are impacted by this vulnerability if all of the following are true: 1. There are 2+ CustomResourceDefinitions sharing the same API group 2. Users have cluster-wide list or watch authorization on one of those custom resources. 3. The same users are not authorized to read another custom resource in the same API group.

View original source

05 / REFERENCES

Further evidence