CVE-2022-1677: Medium severity red hat openshift container platform vulnerability
A user can craft a route that injects a bogus entry into one of the HAProxy configuration files. This bogus entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary application, including one belonging to the user who is performing the attack.
Other sources
In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary application within the cluster, including one under attacker control.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-1677?
CVE-2022-1677 is a vulnerability in OpenShift Container Platform that allows a user to craft a payload that inserts a malformed entry into the cluster router's HAProxy configuration files.
What is the severity of CVE-2022-1677?
The severity of CVE-2022-1677 is medium with a severity value of 6.3.
Which versions of OpenShift Container Platform are affected by CVE-2022-1677?
OpenShift Container Platform versions 3.11, 4.6, 4.7, 4.8, 4.9, and 4.10 are affected by CVE-2022-1677.
How can a user exploit CVE-2022-1677?
A user with permissions to create or modify Routes can exploit CVE-2022-1677 by crafting a payload that inserts a malformed entry into the cluster router's HAProxy configuration files.
Is there a fix available for CVE-2022-1677?
Yes, a fix for CVE-2022-1677 is available. Please refer to the following references for more information: [link1], [link2]