stackrox: Improper sanitization allows users to retrieve Notifier secrets from GraphQL API in plaintext
Published Sep 1, 2022
8.8
HIGHCVSS 3.1
EPSS 1.37%
Description
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.
Affected products
- Vendor n/a Product Red Hat Advanced Cluster Security for Kubernetes Defaultn/a
- Version Red Hat Advanced Cluster Security for Kubernetes 3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Red Hat Advanced Cluster Security for Kubernetes | n/a |
|
- 3.68
- 3.69
- 3.70
No data.
RHACS-3.68-RHEL-8
advanced-cluster-security/rhacs-main-rhel8:3.68.2-8
Fixed · RHSA-2022:5132
RHACS-3.69-RHEL-8
advanced-cluster-security/rhacs-main-rhel8:3.69.2-5
Fixed · RHSA-2022:5188
RHACS-3.70-RHEL-8
advanced-cluster-security/rhacs-main-rhel8:3.70.1-5
Fixed · RHSA-2022:5189
| Product | Package | State | Advisory |
|---|---|---|---|
| RHACS-3.68-RHEL-8 | advanced-cluster-security/rhacs-main-rhel8:3.68.2-8 | Fixed | RHSA-2022:5132 |
| RHACS-3.69-RHEL-8 | advanced-cluster-security/rhacs-main-rhel8:3.69.2-5 | Fixed | RHSA-2022:5188 |
| RHACS-3.70-RHEL-8 | advanced-cluster-security/rhacs-main-rhel8:3.70.1-5 | Fixed | RHSA-2022:5189 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://access.redhat.com/security/cve/CVE-2022-1902 x_refsource_MISCVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2090957 x_refsource_MISCIssue TrackingVendor Advisory
- https://github.com/stackrox/stackrox/pull/1803 x_refsource_MISCExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1902
- https://www.cve.org/CVERecord?id=CVE-2022-1902
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-1902 | x_refsource_MISCVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2090957 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://github.com/stackrox/stackrox/pull/1803 | x_refsource_MISCExploitPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-1902 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-1902 |
Change history (0)
No recorded changes yet.