CVE-2022-39273 is a critical vulnerability affecting FlyteAdmin, the control plane for the Flyte data processing platform. It allows unauthorized access to FlyteAdmin when the default authorization server is enabled without changing hardcoded client ID hashes, which are also present in default Flyte Propeller configurations. This network-exploitable vulnerability has a CVSS score of 7.5 (HIGH), indicating high confidentiality impact, as attackers can impersonate Propeller and gain full access to the system. While no active exploitation, public exploits, or significant community discussion have been observed, affected users should upgrade to version 1.1.44 or manually configure staticClients if using FlyteAdmin's internal auth server.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.44CPE matchmatch criteria | cpe:2.3:a:flyte:flyteadmin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.