← voltar
CVE-2022-2403

CVE-2022-2403

EPSS 0.5%CWE-497
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
01 set 2022Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or service-account. A malicious user could exploit this flaw by reading the oauth-serving-cert ConfigMap in the openshift-config-managed namespace, compromising any web traffic secured using that certificate.
Produtos afetados
n/a · Openshift

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →