CVE-2022-3962 describes a content spoofing vulnerability in Kiali, affecting various Red Hat Enterprise Linux and OpenShift Service Mesh products. This flaw arises from Kiali's lack of error handling for non-existent pages or endpoints, enabling attackers to inject arbitrary text into error responses. Rated Medium severity (CVSS 4.3), it requires user interaction and could lead to low impact on integrity, but does not affect confidentiality or availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, with only one media article covering the vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:kiali:kiali:-:*:*:*:*:*:*:* | ||
2.3.1CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_service_mesh:2.3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.