CVE-2022-3841
published 2023-01-13CVE-2022-3841: RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.9th percentile
RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check, allowing unauthenticated users making requests.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| redhat | advanced_cluster_management_for_kubernetes | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2024-3841
vendor_chrome·2024-05-01·CVSS 6.1
CVE-2024-3841 [MEDIUM] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2024-3841
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2024-3841: Insufficient data validation in Browser Switcher. Reported by Oleg on 2024-03-19 [$5000][ 40058873 ] Low CVE-2024-3844: Inappropriate implementation in Extensions
Reported by Alesandro Ortiz on 2022-02-23 [$2000][ 40064754 ] Low CVE-2024-3846: Inappropriate implementation in Prompts
Severity: medium
Red Hat
RHACM: unauthenticated SSRF in console API endpoint
vendor_redhat·2022-11-02·CVSS 7.8
CVE-2022-3841 [HIGH] CWE-918 RHACM: unauthenticated SSRF in console API endpoint
RHACM: unauthenticated SSRF in console API endpoint
RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check, allowing unauthenticated users making requests.
A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check, allowing unauthenticated users making requests.
Package: rhacm2/console-rhel8 (Red Hat Advanced Cluster Management for Kuberne
GHSA
GHSA-4mp7-jw3w-xgg2: RHACM: unauthenticated SSRF in console API endpoint
ghsa_unreviewed·2023-01-13
CVE-2022-3841 [HIGH] CWE-918 GHSA-4mp7-jw3w-xgg2: RHACM: unauthenticated SSRF in console API endpoint
RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check, allowing unauthenticated users making requests.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-13
Published