PT-2022-5970 · Red Hat · Red Hat Advanced Cluster Security For Kubernetes+1
Oleg Sushchenko
·
Published
2022-11-02
·
Updated
2023-01-20
·
CVE-2022-3841
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Red Hat Advanced Cluster Management for Kubernetes (RHACM) (affected versions not specified)
Red Hat Advanced Cluster Security (RHACS) for Kubernetes (affected versions not specified)
Description
The issue is related to a Server-Side Request Forgery (SSRF) vulnerability, which may allow an attacker to elevate privileges and gain unauthorized access to protected information. An unauthenticated SSRF vulnerability was found in the console API endpoint, missing an authentication check, allowing unauthenticated users to make requests.
Recommendations
For Red Hat Advanced Cluster Management for Kubernetes (RHACM), consider restricting access to the console API endpoint until a patch is available.
For Red Hat Advanced Cluster Security (RHACS) for Kubernetes, as a temporary workaround, consider disabling the vulnerable functionality related to server-side request forgery until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Authentication Bypass Using an Alternate Path or Channel
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat Advanced Cluster Management For Kubernetes
Red Hat Advanced Cluster Security For Kubernetes