Loading HuntDB...

GHSA-qq85-wpwr-7p33

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary application within the cluster, including one under attacker control.

Related CVEs

Key Information

GHSA ID
GHSA-qq85-wpwr-7p33
Published
September 2, 2022 12:01 AM
Last Modified
September 9, 2022 12:00 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 2, 2025 6:46 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.