Bug 2090957 (CVE-2022-1902)
| Summary: | CVE-2022-1902 stackrox: Improper sanitization allows users to retrieve Notifier secrets from GraphQL API in plaintext | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Avinash Hanwate <ahanwate> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED ERRATA | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | sfowler |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: |
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2022-06-28 11:23:04 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2090959, 2090972 | ||
|
Description
Avinash Hanwate
2022-05-27 05:47:39 UTC
This issue has been addressed in the following products: RHACS-3.68-RHEL-8 Via RHSA-2022:5132 https://access.redhat.com/errata/RHSA-2022:5132 This issue has been addressed in the following products: RHACS-3.69-RHEL-8 Via RHSA-2022:5188 https://access.redhat.com/errata/RHSA-2022:5188 This issue has been addressed in the following products: RHACS-3.70-RHEL-8 Via RHSA-2022:5189 https://access.redhat.com/errata/RHSA-2022:5189 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-1902 |