Vulnerability Description
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Advanced Cluster Security | 3.68 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2022-1902Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2090957Issue TrackingVendor Advisory
- https://github.com/stackrox/stackrox/pull/1803ExploitPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-1902Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2090957Issue TrackingVendor Advisory
- https://github.com/stackrox/stackrox/pull/1803ExploitPatchThird Party Advisory
FAQ
What is CVE-2022-1902?
CVE-2022-1902 is a vulnerability with a CVSS score of 8.8 (HIGH). A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifier...
How severe is CVE-2022-1902?
CVE-2022-1902 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-1902?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Advanced Cluster Security.