CVE-2022-23509 is a medium-severity vulnerability affecting Weave GitOps versions prior to v0.12.0, stemming from unencrypted local S3 communication. This allows privileged attackers to intercept traffic, gain access to the S3 bucket, and potentially alter Kubernetes cluster resources. While there is no known active exploitation or public exploit code, and minimal community discussion, the vulnerability carries a CVSS score of 6.0 and a FAUCET Risk Score of 30/100, indicating a significant risk if exploited. Users are advised to upgrade to Weave GitOps version v0.12.0 or later to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.12.0CPE matchmatch criteria | cpe:2.3:a:weave:weave_gitops:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.