Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3841


RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check, allowing unauthenticated users making requests.


Published

2023-01-13T06:15:11.277

Last Modified

2025-04-09T14:15:24.690

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-918
  • Type: Secondary
    CWE-918

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat advanced_cluster_management_for_kubernetes 2.0 Yes

References