CVE detail
CVE-2022-3962 — CVE-2022-3962
Published 2023-09-23 · Modified 2026-06-17 · Vendor kiali · Product kiali · Source nvd
MEDIUM
severity
CVSS-derived band
0.0071
EPSS probability
exploitation probability, 30d
50.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References