Improper access control in StackRox - CVE-2022-1902
Published: June 22, 2022
Vulnerability identifier: #VU64574
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1902
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions to the Notifier secrets. A remote authenticated user retrieve Notifiers from the GraphQL API, obtain secrets and escalate privileges within the application.
Affected software
StackRox
Red Hat Advanced Cluster Security for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
How to mitigate CVE-2022-1902
Install updates from vendor's website.
StackRox - update to 3.70.0
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.68.2, 3.69.2, 3.70.1
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.68.2, 3.69.2, 3.70.1