Vulnerability Description
A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kubernetes | Aws-Iam-Authenticator | >= 0.5.2, < 0.5.9 |
Related Weaknesses (CWE)
References
- https://github.com/kubernetes-sigs/aws-iam-authenticator/issues/472Issue TrackingThird Party Advisory
- https://groups.google.com/a/kubernetes.io/g/dev/c/EMxHpU-1ZYsIssue TrackingMailing ListThird Party Advisory
- https://github.com/kubernetes-sigs/aws-iam-authenticator/issues/472Issue TrackingThird Party Advisory
- https://groups.google.com/a/kubernetes.io/g/dev/c/EMxHpU-1ZYsIssue TrackingMailing ListThird Party Advisory
FAQ
What is CVE-2022-2385?
CVE-2022-2385 is a vulnerability with a CVSS score of 8.1 (HIGH). A security issue was discovered in aws-iam-authenticator where an allow-listed IAM identity may be able to modify their username and escalate privileges.
How severe is CVE-2022-2385?
CVE-2022-2385 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-2385?
Check the references section above for vendor advisories and patch information. Affected products include: Kubernetes Aws-Iam-Authenticator.