ZeroHour

CVE-2022-1902

PoC
CVSS 3.1
8.8 high
EPSS
1%p70
Published
()
Modified
Description

A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.

Vendors
redhat
Products
advanced cluster security
Weakness
CWE-497, CWE-668
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.