Wiz Agents & Workflows are here

CVE-2022-2385
NixOS vulnerability analysis and mitigation

Overview

A high-severity security vulnerability (CVE-2022-2385) was discovered in the AWS IAM Authenticator for Kubernetes, affecting versions v0.5.2 through v0.5.8. The vulnerability, discovered by Gafnit Amiga of Lightspin and disclosed on July 11, 2022, allows an allow-listed IAM identity to modify their username and potentially escalate privileges within the EKS (Elastic Kubernetes Service) cluster (Kubernetes Issue, SecurityOnline).

Technical details

The vulnerability stems from a query parameter validation issue within the authenticator plugin when configured to use the 'AccessKeyID' template parameter within query strings. The flaw allowed attackers to craft malicious tokens with arbitrary action values, bypass cluster ID signing, and manipulate the AccessKeyID value. In clusters using aws-iam-authenticator, if an {{AccessKeyID}} was mapped to an IAM user with cluster admin privileges, any non-privileged user could potentially escalate their privileges to cluster admin. The vulnerability has been assigned a CVSS v3.1 score indicating high severity (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) (CloudVulnDB).

Impact

The vulnerability could enable attackers to escalate privileges within a Kubernetes cluster, potentially gaining unauthorized access to cluster admin privileges. This impact is particularly significant in environments where the AccessKeyID template parameter is used to construct usernames and different access levels are based on these usernames (SecurityOnline).

Mitigation and workarounds

As of June 28, 2022, all EKS clusters worldwide have been automatically updated with a new version of the AWS IAM Authenticator for Kubernetes containing the fix. For self-hosted installations, users should upgrade to aws-iam-authenticator version v0.5.9. As a temporary workaround, users can mitigate the vulnerability by avoiding the use of the {{AccessKeyID}} template value to construct usernames (SecurityOnline, CloudVulnDB).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-2370HIGH8.8
  • GitLabGitLab
  • gitlab-cng-fips-18.8
NoYesMar 30, 2026
CVE-2026-33206HIGH8.2
  • NixOSNixOS
  • calibre
NoYesMar 27, 2026
CVE-2026-33868MEDIUM6.1
  • NixOSNixOS
  • cpe:2.3:a:joinmastodon:mastodon
NoYesMar 27, 2026
CVE-2026-33869MEDIUM4.8
  • NixOSNixOS
  • cpe:2.3:a:joinmastodon:mastodon
NoYesMar 27, 2026
CVE-2026-33205MEDIUM4.8
  • NixOSNixOS
  • cpe:2.3:a:calibre-ebook:calibre
NoYesMar 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management