CVE-2022-4039
Summary
| CVE | CVE-2022-4039 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-22 15:15:00 UTC |
| Updated | 2023-11-07 03:56:00 UTC |
| Description | A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration. |
Risk And Classification
Problem Types: CWE-276
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.10 | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.9 | All | All | All |
| Application | Redhat | Openshift Container Platform For Ibm Z | 4.10 | All | All | All |
| Application | Redhat | Openshift Container Platform For Ibm Z | 4.9 | All | All | All |
| Application | Redhat | Openshift Container Platform For Linuxone | 4.10 | All | All | All |
| Application | Redhat | Openshift Container Platform For Linuxone | 4.9 | All | All | All |
| Application | Redhat | Openshift Container Platform For Power | 4.10 | All | All | All |
| Application | Redhat | Openshift Container Platform For Power | 4.9 | All | All | All |
| Application | Redhat | Single Sign-on | 7.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug Access Denied | MISC | bugzilla.redhat.com | |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MISC | access.redhat.com | |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MISC | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.