A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2023:1047 | Vendor Advisory |
https://access.redhat.com/security/cve/CVE-2022-4039 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2143416 | Issue Tracking Vendor Advisory |
https://access.redhat.com/errata/RHSA-2023:1047 | Vendor Advisory |
https://access.redhat.com/security/cve/CVE-2022-4039 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2143416 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
History
21 Nov 2024, 07:34
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.0 |
References | () https://access.redhat.com/errata/RHSA-2023:1047 - Vendor Advisory | |
References | () https://access.redhat.com/security/cve/CVE-2022-4039 - Vendor Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=2143416 - Issue Tracking, Vendor Advisory |
26 Sep 2023, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-276 | |
First Time |
Redhat openshift Container Platform For Power
Redhat Redhat enterprise Linux Redhat openshift Container Platform Redhat openshift Container Platform For Linuxone Redhat single Sign-on Redhat openshift Container Platform For Ibm Z |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2143416 - Issue Tracking, Vendor Advisory | |
References | (MISC) https://access.redhat.com/errata/RHSA-2023:1047 - Vendor Advisory | |
References | (MISC) https://access.redhat.com/security/cve/CVE-2022-4039 - Vendor Advisory | |
CPE | cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.10:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform_for_power:4.9:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.10:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform:4.9:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.9:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform:4.10:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform_for_power:4.10:*:*:*:*:*:*:* cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.9:*:*:*:*:*:*:* |
22 Sep 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-22 15:15
Updated : 2024-11-21 07:34
NVD link : CVE-2022-4039
Mitre link : CVE-2022-4039
CVE.ORG link : CVE-2022-4039
JSON object : View
Products Affected
redhat
- enterprise_linux
- openshift_container_platform_for_ibm_z
- openshift_container_platform_for_power
- openshift_container_platform
- single_sign-on
- openshift_container_platform_for_linuxone
CWE
CWE-276
Incorrect Default Permissions