Improper access control in StackRox - CVE-2022-1902

 

Improper access control in StackRox - CVE-2022-1902

Published: June 22, 2022


Vulnerability identifier: #VU64574
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1902
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to sensitive information.

The vulnerability exists due to improper access restrictions to the Notifier secrets. A remote authenticated user retrieve Notifiers from the GraphQL API, obtain secrets and escalate privileges within the application.


Affected software

StackRox
Red Hat Advanced Cluster Security for Kubernetes

How to mitigate CVE-2022-1902

Install updates from vendor's website.

StackRox - update to 3.70.0
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.68.2, 3.69.2, 3.70.1

External References

Related Security Bulletins