Back

HIGH

RHACM: unauthenticated SSRF in console API endpoint

Published Jan 11, 2023

Description

RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check, allowing unauthenticated users making requests.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Jan 11, 2023
Updated Apr 9, 2025
Reserved Nov 2, 2022

CISA Vulnrichment

Updated Apr 9, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Nov 2, 2022
Bugzilla 2139426

ENISA EUVD

Assigner redhat
Published Jan 11, 2023
Updated Apr 9, 2025

GitHub

No data