Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-3172

28
FAUCET Score

CVE-2022-3172 is a high-severity vulnerability affecting the Kubernetes API server, specifically allowing an aggregated API server to redirect client traffic to arbitrary URLs. This could lead to clients performing unintended actions and potentially exposing their API server credentials to third parties. The attack has a CVSS score of 8.2 (High) due to its network-based attack vector, low attack complexity, and high confidentiality impact. While there is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.21.14CPE matchmatch criteria
cpe:2.3:a:kubernetes:apiserver:*:*:*:*:*:*:*:*
>= 1.22.0, < 1.22.14CPE matchmatch criteria
cpe:2.3:a:kubernetes:apiserver:*:*:*:*:*:*:*:*
>= 1.23.0, < 1.23.11CPE matchmatch criteria
cpe:2.3:a:kubernetes:apiserver:*:*:*:*:*:*:*:*
>= 1.24.0, < 1.24.5CPE matchmatch criteria
cpe:2.3:a:kubernetes:apiserver:*:*:*:*:*:*:*:*
1.25.0CPE matchmatch criteria
cpe:2.3:a:kubernetes:apiserver:1.25.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.46%
Probability of exploitation in next 30 days
EPSS Percentile
82.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0246 is in the 82nd percentile among its peer group of 14,848 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

check_pointpatch availablevia llm_extracted
View patch
chromepatch availablevia llm_extracted
View patch
infiniflowpatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.12Fixed in: openshift-0:4.12.0-202301042257.p0.g77bec7a.assembly.stream.el9
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.12-RHEL-8Fixed in: odf4/ocs-rhel8-operator:v4.12.4-2
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.12-RHEL-8Fixed in: odf4/odf-rhel8-operator:v4.12.4-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.10Fixed in: openshift-0:4.10.0-202303221742.p0.g16bcd69.assembly.stream.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.11Fixed in: openshift-0:4.11.0-202210122157.p0.g5157800.assembly.stream.el8
View patch
vuepatch availablevia llm_extracted
View patch
github_advisoryvendor investigatingvia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-tests

Vendor Advisories (5)

redhatCVE-2022-3172Moderate

kube-apiserver: Aggregated API server can cause clients to be redirected (SSRF)

Sep 16, 2022
vuellm-vue-46bb97a395ba156a

Aggregated API server can cause clients to be redirected (SSRF)

chromellm-chrome-ee933e9361f1b3cc

Aggregated API server can cause clients to be redirected (SSRF)

check_pointllm-check_point-805937892feec394

Aggregated API server can cause clients to be redirected (SSRF)

infiniflowllm-infiniflow-d18d1de17c7c5dc6

Aggregated API server can cause clients to be redirected (SSRF)

References

github.com / kubernetes/kubernetes/issues/112513
Issue TrackingVendor Advisory
groups.google.com / g/kubernetes-security-announce/c/_aLzYMpPRak
Mailing List
security.netapp.com / advisory/ntap-20231221-0005