NA

CVE-2022-4039

Published: 22/09/2023 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an malicious user to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat single sign-on 7.0

redhat openshift container platform 4.9

redhat openshift container platform 4.10

redhat openshift container platform for ibm z 4.9

redhat openshift container platform for ibm z 4.10

redhat openshift container platform for linuxone 4.9

redhat openshift container platform for linuxone 4.10

redhat openshift container platform for power 4.9

redhat openshift container platform for power 4.10

Vendor Advisories

Synopsis Important: Red Hat Single Sign-On 762 for OpenShift image security and enhancement update Type/Severity Security Advisory: Important Topic A new image is available for Red Hat Single Sign-On 762, running on RedHat OpenShift Container Platform from the release of 311 up to the releaseof 4120Red Hat Product Security has rated t ...
Description<!---->A flaw was found in Keycloak Instances launched by the Operator are configured with an unsecured management interface enabled This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configurationA flaw was found in Keycloak Instances ...