VendorsRed Hatadvanced_cluster_management_for_kubernetes2.0
Vulnerabilities

Red Hat Advanced Cluster Management 2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2022-3841
RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check, allowing unauthenticated users making requests.
Published 2023-01-11 · Modified
7.8EPSS 0.002
CVE-2026-71845
Insights-client: insights-client: ccx_token bearer credential logged in clear text at startup via setdefault()
Published 2026-08-11 · Modified
7.7EPSS 0.005
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2022-27191
The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
Published 2022-03-18 · Modified
7.5EPSS 0.039
CVE-2025-14874
Nodemailer: nodemailer: denial of service via crafted email address header
Published 2025-12-18 · Modified
7.5EPSS 0.006
CVE-2022-3248
Openshift api admission checks does not enforce "custom-host" permissions
Published 2023-10-05 · Modified
7.5EPSS 0.004
CVE-2026-71474
Insights-client-rhel9: insights-client: pull-secret bearer token written to logs on non-200 ccx response
Published 2026-08-11 · Modified
7.1EPSS 0.002
CVE-2026-71475
Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path
Published 2026-08-11 · Modified
6.8EPSS 0.007
CVE-2022-2238
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability while restarting.
Published 2022-09-01 · Modified
6.5EPSS 0.009
CVE-2020-25655
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster secrets that should only be disclosed to admin users.
Published 2020-11-09 · Modified
6.5EPSS 0.006
CVE-2026-71846
Insights-client: insights-client: clusterrole grants cluster-wide secrets get/list/watch beyond least privilege
Published 2026-08-12 · Modified
6.5EPSS 0.002