CVE-2022-1677
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
01/09/2022
Last modified:
12/02/2023
Description
In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary application within the cluster, including one under attacker control.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:openshift_container_platform:4.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:openshift_container_platform:4.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:openshift_container_platform:4.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:openshift_container_platform:4.9:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:openshift_container_platform:4.10:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



