FlawAtlas
Search the atlas
CVE-2022-3294 Moderate

Kubernetes vulnerable to validation bypass in k8s.io/kubernetes

Kubernetes vulnerable to validation bypass in k8s.io/kubernetes

Exploit probability 1.6%
Published August 20, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

203 explicit affected versions

Go k8s.io/kubernetes
Go github.com/kubernetes/kubernetes

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2023-1629

Kubernetes vulnerable to validation bypass in k8s.io/kubernetes

View original source
Open Source Vulnerabilities GHSA-jh36-q97c-9928

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server's private network.

View original source
Open Source Vulnerabilities CVE-2022-3294

Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untrusted user can modify Node objects and send proxy requests to them. Kubernetes supports node proxying, which allows clients of kube-apiserver to access endpoints of a Kubelet to establish connections to Pods, retrieve container logs, and more. While Kubernetes already validates the proxying address for Nodes, a bug in kube-apiserver made it possible to bypass this validation. Bypassing this validation could allow authenticated requests destined for Nodes to to the API server's private network.

View original source

05 / REFERENCES

Further evidence