Medium severity4.3NVD Advisory· Published Sep 23, 2023· Updated Jun 17, 2026
CVE-2022-3962
CVE-2022-3962
Description
A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/kiali/kialiGo | < 1.57.4 | 1.57.4 |
Affected products
11- Red Hat/Red Hat OpenShift Service Mesh 2.3 for RHEL 8v5cpe:/a:redhat:service_mesh:2.3::el8Range: 1.57.5-3
cpe:2.3:a:redhat:openshift_service_mesh:2.3.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_service_mesh:2.3.1:*:*:*:*:*:*:*
- cpe:/a:redhat:service_mesh:2.1
- ghsa-coords7 versionspkg:golang/github.com/kiali/kialipkg:apk/chainguard/kiali-uipkg:apk/wolfi/kiali-apipkg:apk/chainguard/kialipkg:apk/chainguard/kiali-apipkg:apk/wolfi/kialipkg:apk/wolfi/kiali-ui
< 1.57.4+ 6 more
- (no CPE)range: < 1.57.4
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
Patches
Vulnerability mechanics
References
7- access.redhat.com/errata/RHSA-2023:0542nvdThird Party AdvisoryWEB
- access.redhat.com/security/cve/CVE-2022-3962nvdThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-6f4m-j56w-55c3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-3962ghsaADVISORY
- github.com/kiali/kiali/commit/aab7694f850f04d7fd875fac5f720a93ccdf01adghsaWEB
- issues.redhat.com/browse/OSSM-2251ghsaWEB
News mentions
0No linked articles in our index yet.