CVE-2022-3172
Kubernetes - API server - Aggregated API server can cause clients to be redirected (SSRF)
- Published
- Nov 3, 2023
- Updated
- Feb 13, 2025
- Assigning CNA
- kubernetes
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:NLow · next 30 days
- Percentile
- 83.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.
Sources
1Proof-of-concept exploit for CVE-2022-3172 in Kubernetes, demonstrating unauthorized access to metrics API via a crafted token.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.