PT-2022-5970 · Red Hat · Red Hat Advanced Cluster Security For Kubernetes+1

Oleg Sushchenko

·

Published

2022-11-02

·

Updated

2023-01-20

·

CVE-2022-3841

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Red Hat Advanced Cluster Management for Kubernetes (RHACM) (affected versions not specified) Red Hat Advanced Cluster Security (RHACS) for Kubernetes (affected versions not specified)
Description The issue is related to a Server-Side Request Forgery (SSRF) vulnerability, which may allow an attacker to elevate privileges and gain unauthorized access to protected information. An unauthenticated SSRF vulnerability was found in the console API endpoint, missing an authentication check, allowing unauthenticated users to make requests.
Recommendations For Red Hat Advanced Cluster Management for Kubernetes (RHACM), consider restricting access to the console API endpoint until a patch is available. For Red Hat Advanced Cluster Security (RHACS) for Kubernetes, as a temporary workaround, consider disabling the vulnerable functionality related to server-side request forgery until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass Using an Alternate Path or Channel

SSRF

Weakness Enumeration

Related Identifiers

BDU:2022-07398
CVE-2022-3841

Affected Products

Red Hat Advanced Cluster Management For Kubernetes
Red Hat Advanced Cluster Security For Kubernetes