CVE-2022-2385: AccessKeyID validation bypass
Published Jul 12, 2022
·Updated
A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.
Affected Software
1 affected component
Kubernetes Aws-iam-authenticator Kubernetes>=0.5.2<0.5.9
Event History
Jul 12, 2022
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2385?
The severity of CVE-2022-2385 is high.
2
What is the description of CVE-2022-2385?
CVE-2022-2385 is a security issue in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.
3
Which software is affected by CVE-2022-2385?
Kubernetes Aws-iam-authenticator versions 0.5.2 to 0.5.9 are affected by CVE-2022-2385.
4
How can an IAM identity modify their username and escalate privileges in CVE-2022-2385?
An allow-listed IAM identity can modify their username and escalate privileges in CVE-2022-2385.
5
Where can I find more information about CVE-2022-2385?
You can find more information about CVE-2022-2385 on the GitHub issue and Google Groups discussion linked in the references.