← Vulnerability feed

Vulnerability record · CVE-2022-1902 · published 1 September 2022

CVE-2022-1902: Redhat advanced cluster security exposure of resource to wrong sphere vulnerability

Redhat · Advanced Cluster Security

A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.

8.8 CVSS 3.1 High EPSS 1.4% · top 29.0% CWE-497 · CWE-497CWE-668 · Exposure of resource to wrong sphere
8.8CVSS 3.1 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-1902 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.8CVE-2024-0406Mholt archiver path traversal vulnerabilityA flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may a…EPSS 0.93%7.7CVE-2026-44495Axios code injection vulnerabilityAxios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets…EPSS 1.0%6.1CVE-2023-4958Redhat advanced cluster security clickjacking vulnerabilityIn Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this…EPSS 0.63%5.9CVE-2023-48795SSH Terrapin attack downgrades channel integrity in OpenSSH and many SSH implementationsThe SSH transport protocol with certain OpenSSH extensions mishandles the handshake and sequence numbers, letting a remote attacker omit packets from…EPSS 94%analysed5.4CVE-2025-5198Redhat advanced cluster security cross-site scripting vulnerabilityA flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. T…EPSS 0.28%5.5CVE-2021-31955Windows Kernel information disclosure flawCVE-2021-31955 is an information disclosure vulnerability in the Windows kernel affecting multiple Windows 10 and Windows Server builds. The record g…KEVEPSS 81%analysed

Source: NIST National Vulnerability Database (record CVE-2022-1902), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.