Bug 2112758 - CVE-2022-3248 openshift-clients: kubernetes: OpenShift API admission checks does not enforce "custom-host" permissions [openshift-4]
Summary: CVE-2022-3248 openshift-clients: kubernetes: OpenShift API admission checks d...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Deadline: 2022-09-19
Product: OpenShift Container Platform
Classification: Red Hat
Component: oc
Version: 4.12
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
: 4.12.z
Assignee: Nobody
QA Contact: zhou ying
URL:
Whiteboard: component:openshift-clients
Depends On:
Blocks: CVE-2022-3248
TreeView+ depends on / blocked
 
Reported: 2022-08-01 05:16 UTC by Avinash Hanwate
Modified: 2024-04-30 18:04 UTC (History)
9 users (show)

Fixed In Version:
Doc Type: No Doc Update
Doc Text:
Clone Of:
Environment:
Last Closed: 2024-04-30 18:04:53 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Avinash Hanwate 2022-08-01 05:16:53 UTC
openshift-4 tracking bug for openshift-clients: see the bugs linked in the "Blocks" field of this bug for full details of the security issue(s).

This bug is never intended to be made public, please put any public notes in the blocked bugs.

Impact: Low
Reported Date: 23-Mar-2022
PM Fix/Wontfix Decision By: 31-Aug-2022
Resolve Bug By: 23-Mar-2023

In case the dates above are already past, please evaluate this bug in your next prioritization review and make a decision then. Remember to explicitly set CLOSED:WONTFIX if you decide not to fix this bug.

Please see the Security Errata Policy for further details: https://docs.engineering.redhat.com/x/9RBqB

NOTE THIS ISSUE IS CURRENTLY EMBARGOED, DO NOT MAKE PUBLIC COMMITS OR COMMENTS ABOUT THIS ISSUE.

WARNING: NOTICE THAT REMOVING THE "SECURITY" GROUP FROM THIS TRACKER MAY BREAK THE EMBARGO.

Comment 11 Rory Thrasher 2024-04-30 18:04:53 UTC
OCP is no longer using Bugzilla and this bug appears to have been left in an orphaned state. If the bug is still relevant, please open a new issue in the OCPBUGS Jira project: https://issues.redhat.com/projects/OCPBUGS/summary


Note You need to log in before you can comment on or make changes to this bug.