CVE Vulnerabilities

CVE-2022-3841

Server-Side Request Forgery (SSRF)

Published: Jan 13, 2023 | Modified: Apr 09, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Ubuntu
root.io logo minimus.io logo echo.ai logo

RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check, allowing unauthenticated users making requests.

Weakness

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Affected Software

NameVendorStart VersionEnd Version
Advanced_cluster_management_for_kubernetesRedhat2.0 (including)2.0 (including)
Red Hat Advanced Cluster Management for Kubernetes 2RedHatacm-governance-policy-addon-controller-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatacm-grafana-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatacm-must-gather-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatacm-operator-bundle-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatacm-prometheus-config-reloader-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatacm-prometheus-operator-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatacm-volsync-addon-controller-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatcert-policy-controller-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatcluster-backup-operator-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatconfig-policy-controller-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatconsole-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatendpoint-monitoring-operator-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatgovernance-policy-propagator-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatgovernance-policy-spec-sync-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatgovernance-policy-status-sync-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatgovernance-policy-template-sync-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatgrafana-dashboard-loader-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatiam-policy-controller-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatinsights-client-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatinsights-metrics-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatklusterlet-addon-controller-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatkube-rbac-proxy-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatkube-state-metrics-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatmanagement-ingress-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatmemcached-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatmemcached-exporter-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatmetrics-collector-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatmulticloud-integrations-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatmulticlusterhub-operator-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatmulticlusterhub-repo-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatmulticluster-observability-operator-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatmulticluster-operators-application-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatmulticluster-operators-channel-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatmulticluster-operators-subscription-operator-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatnode-exporter-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatobservatorium-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatobservatorium-operator-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatprometheus-alertmanager-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatprometheus-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatrbac-query-proxy-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatredisgraph-tls-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatsearch-aggregator-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatsearch-api-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatsearch-collector-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatsearch-operator-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatsubmariner-addon-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatthanos-container*
Red Hat Advanced Cluster Management for Kubernetes 2RedHatthanos-receive-controller-container*
Red Hat Advanced Cluster Management for Kubernetes 2.7 for RHEL 8RedHatrhacm2/console-rhel8:v2.7.3-16*

References