In Red Hat Advanced Cluster Security for Kubernetes, it was found that Notifier secrets were not properly sanitized in the GraphQL API. Authenticated ACS users could exploit this by retrieving Notifiers from the GraphQL API, revealing secrets that could then be used to escalate their privileges. https://github.com/stackrox/stackrox/pull/1803
This issue has been addressed in the following products: RHACS-3.68-RHEL-8 Via RHSA-2022:5132 https://access.redhat.com/errata/RHSA-2022:5132
This issue has been addressed in the following products: RHACS-3.69-RHEL-8 Via RHSA-2022:5188 https://access.redhat.com/errata/RHSA-2022:5188
This issue has been addressed in the following products: RHACS-3.70-RHEL-8 Via RHSA-2022:5189 https://access.redhat.com/errata/RHSA-2022:5189
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-1902