CVE-2022-23652: Clastix Capsule-Proxy

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

capsule-proxy is a reverse proxy for Capsule Operator which provides multi-tenancy in Kubernetes. In versions prior to 0.2.1 an attacker with a proper authentication mechanism may use a malicious `Connection` header to start a privilege escalation attack towards the Kubernetes API Server. This vulnerability allows for an exploit of the `cluster-admin` Role bound to `capsule-proxy`. There are no known workarounds for this issue.

Affected products

  • Clastix Capsule-Proxy: before 0.2.1 (fixed in 0.2.1)

Published 2022-02-22. Last modified 2026-06-17.