6.5
CVSSv3

CVE-2022-2238

Published: 01/09/2022 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an malicious user to craft specific strings containing special characters that lead to crashing the pod and affects system availability while restarting.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat advanced cluster management for kubernetes 2.0

Vendor Advisories

Synopsis Moderate: Red Hat Advanced Cluster Management 248 security fixes and container updates Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 248 GeneralAvailability release images, which fix security issuesRed Hat Product Security has rated this update as having a security impactof Mo ...
Synopsis Moderate: Red Hat Advanced Cluster Management 253 security fixes and bug fixes Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 253 GeneralAvailability release images, which fix security issues and bugs, as well as update container imagesRed Hat Product Security has rated this up ...
Synopsis Moderate: Red Hat Advanced Cluster Management 262 security update and bug fixes Type/Severity Security Advisory: Moderate Topic Red Hat Advanced Cluster Management for Kubernetes 262 GeneralAvailability release images, which fix bugs and update container imagesRed Hat Product Security has rated this update as having a security i ...
A vulnerability was found in the search-api container when a query in the search filter gets parsed by the backend This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability while restarting ...