CVE-2022-23551 affects Azure AD Pod Identity, a deprecated component for assigning Azure AD identities to Kubernetes applications. The vulnerability allows a malicious pod to bypass NMI validation by using a backslash in token requests, gaining unauthorized access to other identities. Rated Medium (CVSS 5.3), it requires high privileges and user interaction, potentially leading to limited confidentiality, high integrity, and limited availability impacts. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.13CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_ad_pod_identity:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-23551
Feb 13, 2024AAD Pod Identity obtaining token with backslash
Dec 21, 2022aad-pod-identity: authentication bypass via backslash
Dec 21, 2022AAD Pod Identity obtaining token with backslash
Dec 13, 2022