CVE-2022-1902
01.09.2022, 21:15
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | advanced_cluster_security | 3.68 |
redhat | advanced_cluster_security | 3.69 |
redhat | advanced_cluster_security | 3.70 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control SphereThe application does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the application does.
- CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
References