SB2023022167 - OpenShift Container Platform 4.12 update for kubernetes 



SB2023022167 - OpenShift Container Platform 4.12 update for kubernetes

Published: February 21, 2023

Security Bulletin ID SB2023022167
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2022-3162)

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a different kind in the same API group they are not authorized to read.


Remediation

Install update from vendor's website.