Vulnerability record · CVE-2022-1902 · published 1 September 2022
CVE-2022-1902: Redhat advanced cluster security exposure of resource to wrong sphere vulnerability
Redhat · Advanced Cluster Security
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.
Description
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/security/cve/CVE-2022-1902 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2090957 | Issue TrackingVendor Advisory |
| https://github.com/stackrox/stackrox/pull/1803 | ExploitPatchThird Party Advisory |
| https://access.redhat.com/security/cve/CVE-2022-1902 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2090957 | Issue TrackingVendor Advisory |
| https://github.com/stackrox/stackrox/pull/1803 | ExploitPatchThird Party Advisory |
Track CVE-2022-1902 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-1902), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.