MEDIUM🇵🇱 Wersja polska

CVE-2022-23551

CVSS 5.3v3.1pub. 2022-12-21upd. 2024-11-21

aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request made with backslash in the request (example: `/metadata/identity\oauth2\token/`) would bypass the NMI validation and be sent to IMDS allowing a pod in the cluster to access identities that it shouldn't have access to. This issue has been fixed and has been included in AAD Pod Identity release version 1.8.13. If using the AKS pod-managed identities add-on, no action is required. The clusters should now be running the version 1.8.13 release.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:L
  • Microsoft Azure Ad Pod Identity

    APP
    Microsoft
    < 1.8.13
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2026-58644CRITICAL9.8⚠ KEVPL ✓same vendor

Zdalne wykonanie kodu poprzez deserializację w Microsoft SharePoint Server

CVE-2026-50522CRITICAL9.8⚠ KEVPL ✓same vendor

RCE przez deserializację niezaufanych danych w Microsoft SharePoint

CVE-2026-55040CRITICAL9.1⚠ KEVPL ✓same vendor

Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same vendor

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same vendor

Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu