CVE-2022-3962: Kiali: error message spoofing in kiali ui
A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3962?
CVE-2022-3962 is a content spoofing vulnerability found in Kiali.
How does CVE-2022-3962 affect Kiali?
CVE-2022-3962 allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed in Kiali.
What is the severity of CVE-2022-3962?
CVE-2022-3962 has a severity level of medium.
How do I fix CVE-2022-3962 in Kiali?
To fix CVE-2022-3962 in Kiali, you need to upgrade to version 2.3.1 or later.
Where can I find more information about CVE-2022-3962?
You can find more information about CVE-2022-3962 at the following references: [CVE-2022-3962](https://www.cve.org/CVERecord?id=CVE-2022-3962), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-3962), [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2148661), [Red Hat](https://access.redhat.com/errata/RHSA-2023:0542).