Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-23509

21
FAUCET Score

CVE-2022-23509 is a medium-severity vulnerability affecting Weave GitOps versions prior to v0.12.0, stemming from unencrypted local S3 communication. This allows privileged attackers to intercept traffic, gain access to the S3 bucket, and potentially alter Kubernetes cluster resources. While there is no known active exploitation or public exploit code, and minimal community discussion, the vulnerability carries a CVSS score of 6.0 and a FAUCET Risk Score of 30/100, indicating a significant risk if exploited. Users are advised to upgrade to Weave GitOps version v0.12.0 or later to remediate this issue.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.12.0CPE matchmatch criteria
cpe:2.3:a:weave:weave_gitops:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.7
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 61st percentile among its peer group of 3,720 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/weaveworks/weave-gitopsFixed in: 0.12.0

Vendor Advisories (1)

goGHSA-89qm-wcmw-3mgghigh

Gitops Run insecure communication

Jan 9, 2023

References

github.com / weaveworks/weave-gitops/pull/3098/commits/babd91574b99b310b84aeec9f8f895bd18acb967
PatchThird Party Advisory
github.com / weaveworks/weave-gitops/pull/3106/commits/ce2bbff0a3609c33396050ed544a5a21f8d0797f
PatchThird Party Advisory
github.com / weaveworks/weave-gitops/security/advisories/GHSA-89qm-wcmw-3mgg
Third Party Advisory