CVE-2022-2238
published 2022-09-01CVE-2022-2238: A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by…
PriorityP334medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.82%
53.5th percentile
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability while restarting.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | advanced_cluster_management_for_kubernetes | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ManageEngine: remote code execution vulnerability in multiple ManageEngine products
vendor_redhat·2023-01-19·CVSS 9.8
CVE-2022-47966 [CRITICAL] CWE-303 ManageEngine: remote code execution vulnerability in multiple ManageEngine products
ManageEngine: remote code execution vulnerability in multiple ManageEngine products
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus
Red Hat
search-api: SQL injection leads to remote denial of service
vendor_redhat·2022-06-28·CVSS 6.5
CVE-2022-2238 [MEDIUM] CWE-89 search-api: SQL injection leads to remote denial of service
search-api: SQL injection leads to remote denial of service
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability while restarting.
A vulnerability was found in the search-api container when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability while restarting.
Statement: In Red Hat Advanced Cluster Management for Kubernetes (RHACM) the search-api component is protected by OpenShi
GHSA
GHSA-gpp7-gqhm-5827: A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets par
ghsa_unreviewed·2022-09-02
CVE-2022-2238 [MEDIUM] CWE-89 GHSA-gpp7-gqhm-5827: A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets par
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability while restarting.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-09-01
Published