CVE-2022-41939

CVSS V2 None CVSS V3 High 7.4
Description
knative.dev/func is is a client library and CLI enabling the development and deployment of Kubernetes functions. Developers using a malicious or compromised third-party buildpack could expose their registry credentials or local docker socket to a malicious `lifecycle` container. This issues has been patched in PR #1442, and is part of release 1.8.1. This issue only affects users who are using function buildpacks from third-parties; pinning the builder image to a specific content-hash with a valid `lifecycle` image will also mitigate the attack.
Overview
  • CVE ID
  • CVE-2022-41939
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-11-19T01:15:13
  • Last Modified Date
  • 2023-03-14T15:35:40
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:cncf:knative_func:*:*:*:*:*:*:*:* 1 OR 1.8.1
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • REQUIRED
  • Scope
  • CHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • NONE
  • Base Score
  • 7.4
  • Base Severity
  • HIGH
  • Exploitability Score
  • 2.8
  • Impact Score
  • 4
History
Created Old Value New Value Data Type Notes
2022-11-19 02:00:14 Added to TrackCVE
2022-12-07 17:55:44 2022-11-19T01:15Z 2022-11-19T01:15:13 CVE Published Date updated
2022-12-07 17:55:44 2022-11-26T03:21:28 CVE Modified Date updated
2022-12-07 17:55:44 Analyzed Vulnerability Status updated
2022-12-07 17:55:46 CPE Information updated
2023-03-14 16:15:24 2023-03-14T15:35:40 CVE Modified Date updated