Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0936 | capsule-proxy is a reverse proxy for Capsule Operator which provides multi-tenancy in Kubernetes. In versions prior to 0.2.1 an attacker with a proper authentication mechanism may use a malicious `Connection` header to start a privilege escalation attack towards the Kubernetes API Server. This vulnerability allows for an exploit of the `cluster-admin` Role bound to `capsule-proxy`. There are no known workarounds for this issue. |
Github GHSA |
GHSA-9cwv-cppx-mqjm | Improper Authentication in Capsule Proxy |
Tue, 22 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-22T18:21:44.645Z
Reserved: 2022-01-19T00:00:00.000Z
Link: CVE-2022-23652
Updated: 2024-08-03T03:51:45.543Z
Status : Modified
Published: 2022-02-22T20:15:07.763
Modified: 2024-11-21T06:49:01.510
Link: CVE-2022-23652
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA