CVE Database
/

CVE-2022-1902

Back to search

CVE-2022-1902

Published: Sep 1, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.

VendorProductVersions

n/a

Red Hat Advanced Cluster Security for Kubernetes

affected
Red Hat Advanced Cluster Security for Kubernetes 3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now