CVE-2022-31077
vulnerability analysis and mitigation

Overview

KubeEdge, a platform built upon Kubernetes that extends native containerized application orchestration and device management to Edge hosts, was found to contain a vulnerability where a malicious message response could crash the CSI Driver controller server. The vulnerability (CVE-2022-31077) was discovered in June 2022 and affected versions <=1.10.0, 1.9.2, and 1.8.2. The issue was patched in versions 1.11.0, 1.10.1, and 1.9.3 (GitHub Advisory).

Technical details

The vulnerability involves a nil-pointer dereference panic that can be triggered by a malicious message response from KubeEdge. The issue was discovered through fuzzing KubeEdge via OSS-Fuzz. The vulnerability has a CVSS v3.1 base score of 4.0 (Moderate) with the following vector: CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H. The attack requires adjacent network access, high attack complexity, high privileges, and user interaction (GitHub Advisory).

Impact

When exploited, the vulnerability results in a denial of service condition for the CSI Driver controller. The attack only affects availability, with no impact on confidentiality or integrity. The scope is unchanged, meaning the vulnerable component cannot impact resources beyond its security scope (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in KubeEdge versions 1.11.0, 1.10.1, and 1.9.3. Users are advised to update to these patched versions to resolve the issue. No workarounds were available at the time of the vulnerability disclosure (GitHub Advisory).

Community reactions

The vulnerability was responsibly disclosed by David Korczynski and Adam Korczynski of ADA Logics during a security audit sponsored by CNCF and facilitated by OSTIF. The issue was discovered through the OSS-Fuzz program, demonstrating the effectiveness of continuous fuzzing in identifying security vulnerabilities (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management