HIGH 8.8 Go

Improper Authentication in Capsule Proxy

GHSA-9cwv-cppx-mqjm · CVE-2022-23652 · GO-2022-0329

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Using a malicious Connection header, an attacker with a proper authentication mechanism could start a privilege escalation towards the Kubernetes API Server, being able to exploit the cluster-admin Role bound to capsule-proxy.

Patches

Patch has been merged in the v0.2.1 release.

Workarounds

Upgrading is mandatory.

Ready to move

Start Securing

Free, no credit card | First findings in minutes