CVE-2022-1902 is a high-severity vulnerability affecting Red Hat Advanced Cluster Security for Kubernetes, where the GraphQL API fails to properly sanitize Notifier secrets. This flaw allows authenticated users to retrieve sensitive Notifier secrets, potentially leading to privilege escalation. With a CVSS score of 8.8 (High), the vulnerability is network-exploitable with low attack complexity and no user interaction required, posing a significant risk of high confidentiality, integrity, and availability impact. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there is minimal community discussion or media coverage, the FAUCET Risk Score of 71/100 indicates a notable potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.68CPE matchmatch criteria | cpe:2.3:a:redhat:advanced_cluster_security:3.68:*:*:*:*:kubernates:*:* | ||
3.69CPE matchmatch criteria | cpe:2.3:a:redhat:advanced_cluster_security:3.69:*:*:*:*:kubernates:*:* | ||
3.70CPE matchmatch criteria | cpe:2.3:a:redhat:advanced_cluster_security:3.70:*:*:*:*:kubernates:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.