Lucene search

K
cveRedhatCVE-2022-1902
HistorySep 01, 2022 - 9:15 p.m.

CVE-2022-1902

2022-09-0121:15:09
CWE-497
CWE-668
redhat
web.nvd.nist.gov
1899
2
red hat
advanced cluster security
kubernetes
notifier
graphql api
authentication
acs
secrets
privilege escalation
cve-2022-1902

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.002

Percentile

64.4%

A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.

Affected configurations

Nvd
Vulners
Node
redhatadvanced_cluster_securityMatch3.68kubernates
OR
redhatadvanced_cluster_securityMatch3.69kubernates
OR
redhatadvanced_cluster_securityMatch3.70kubernates
VendorProductVersionCPE
redhatadvanced_cluster_security3.68cpe:2.3:a:redhat:advanced_cluster_security:3.68:*:*:*:*:kubernates:*:*
redhatadvanced_cluster_security3.69cpe:2.3:a:redhat:advanced_cluster_security:3.69:*:*:*:*:kubernates:*:*
redhatadvanced_cluster_security3.70cpe:2.3:a:redhat:advanced_cluster_security:3.70:*:*:*:*:kubernates:*:*

CNA Affected

[
  {
    "product": "Red Hat Advanced Cluster Security for Kubernetes",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Red Hat Advanced Cluster Security for Kubernetes 3"
      }
    ]
  }
]

Social References

More

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.002

Percentile

64.4%