PT-2022-3650 · Red Hat · Red Hat Advanced Cluster Security For Kubernetes

Avinash Hanwate

·

Published

2022-05-27

·

Updated

2023-02-13

·

CVE-2022-1902

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Red Hat Advanced Cluster Security for Kubernetes (affected versions not specified)
Description A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes, related to insufficient protection of service data in the GraphQL API. This issue allows authenticated users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges. The flaw is associated with the inadequate sanitization of Notifier secrets in the GraphQL API.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BDU:2022-04435
CVE-2022-1902

Affected Products

Red Hat Advanced Cluster Security For Kubernetes