NA

CVE-2022-4039

Published: 22/09/2023 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an malicious user to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat single sign-on 7.0

redhat openshift_container_platform 4.9

redhat openshift_container_platform 4.10

redhat openshift_container_platform_for_ibm_z 4.9

redhat openshift_container_platform_for_ibm_z 4.10

redhat openshift_container_platform_for_linuxone 4.9

redhat openshift_container_platform_for_linuxone 4.10

redhat openshift_container_platform_for_power 4.9

redhat openshift_container_platform_for_power 4.10

Vendor Advisories

Synopsis Important: Red Hat Single Sign-On 762 for OpenShift image security and enhancement update Type/Severity Security Advisory: Important Topic A new image is available for Red Hat Single Sign-On 762, running on RedHat OpenShift Container Platform from the release of 311 up to the releaseof 4120Red Hat Product Security has rated t ...
Description<!---->A flaw was found in Keycloak Instances launched by the Operator are configured with an unsecured management interface enabled This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configurationA flaw was found in Keycloak Instances ...