Back

MEDIUM

search-api: SQL injection leads to remote denial of service

Published Sep 1, 2022

Description

A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability while restarting.

Affected products

Remediation

Red Hat statement

In Red Hat Advanced Cluster Management for Kubernetes (RHACM) the search-api component is protected by OpenShift OAuth which reduces the impact of this flaw to Moderate. Access to the search-api where queries can be submitted requires the user or ServiceAccount token authorization with a granted access to the resources and managed clusters.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Sep 1, 2022
Updated Aug 3, 2024
Reserved Jun 28, 2022

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jun 28, 2022
Bugzilla 2101669

ENISA EUVD

Assigner redhat
Published Sep 1, 2022
Updated Aug 3, 2024

GitHub

No data