🕳️ Vulnerabilities & CVEs

CVE-2022-3172: Kube-Apiserver's Redirect to Credential Hell

Kubernetes clusters? Compromised by a sneaky redirect in kube-apiserver. CVE-2022-3172 hands attackers your traffic – and your secrets.

Kubernetes kube-apiserver redirecting traffic to malicious URL in CVE-2022-3172 vulnerability

⚡ Key Takeaways

  • CVE-2022-3172 allows arbitrary redirects from aggregated API servers, exposing bearer tokens. 𝕏
  • Affects most Kubernetes setups with extensions; patches available since late 2022. 𝕏
  • Unique risk: Turns trusted API extensions into phishing vectors for cluster takeover. 𝕏
Published by

theAIcatchup

Threat intelligence. Zero noise.

Worth sharing?

Get the best Cybersecurity stories of the week in your inbox — no noise, no spam.

Originally reported by NVD Vulnerabilities

Stay in the loop

The week's most important stories from theAIcatchup, delivered once a week.