Back to Labs
Security Advisory

CVE-2022-31358

About

A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.

Weakness (CWE):CWE-79

Rainforest analyst review

Proxmox Virtual Environment has a reflected cross-site scripting flaw reachable via non-existent endpoints under /api2/html/: a crafted link to one of those bogus paths reflects attacker script back into the response, executing in the browser of a victim who follows it. What raises this above a routine XSS is the target — Proxmox VE is a hypervisor management console, so script running in an authenticated admin's session touches the control plane for whole fleets of virtual machines.

The vector shows the brakes and the amplifiers together: it needs low-privileged authentication and user interaction (an admin clicking the link), but the scope is changed and the impact spans confidentiality, integrity, and availability, reflecting that riding a virtualization admin's session is consequential. Realistically this is a targeted, phishing-delivered attack against a Proxmox operator rather than mass exploitation, but the payoff — acting within the session that manages the virtualization estate — is why it lands at the high end of XSS severity.

Our emphasis is exposure isolation and session protection for the management plane. Proxmox web UIs should never be broadly reachable, so we'd confirm any instance below v7.2-3 sits behind VPN or tight IP restrictions, shrinking the set of admins who could be lured while authenticated, and drive the upgrade on the hypervisor-management priority track. Where we can, watching for requests to the malformed /api2/html/ paths gives a clean detection signature while patching proceeds.

References

Related CVEs

Frequently asked questions

What is CVE-2022-31358?

A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.

How severe is CVE-2022-31358?

CVE-2022-31358 carries a CVSS 3.1 base score of 9, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 90 out of 100, in the critical band.

How is CVE-2022-31358 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required Low, user interaction Required. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2022-31358?

Public advisories list the following as affected: virtual environment. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2022-31358?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email