Medium severity4.4NVD Advisory· Published Oct 5, 2023· Updated Jun 17, 2026
CVE-2022-3248
CVE-2022-3248
Description
A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:/a:redhat:acm:2+ 1 more
- cpe:/a:redhat:acm:2
- cpe:2.3:a:redhat:advanced_cluster_management_for_kubernetes:2.0:*:*:*:*:*:*:*
- cpe:/a:redhat:ansible_automation_platform
- cpe:/a:redhat:ansible_tower:3
cpe:/a:redhat:openshift:3.11+ 2 more
- cpe:/a:redhat:openshift:3.11
- cpe:/a:redhat:openshift:4
- cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- access.redhat.com/security/cve/CVE-2022-3248nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.