Redhat Advanced Cluster Security vulnerabilities
6 known vulnerabilities affecting redhat/advanced_cluster_security.
Total CVEs
6
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
HIGH3MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2025-5198MEDIUMCVSS 5.4v4.02025-05-27
CVE-2025-5198 [MEDIUM] CWE-79 CVE-2025-5198: A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script cod
A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the name of a Kubernetes “Role” object* that is applied to a secured cluster. This object can be used by a user with access to the cluster or
nvd
CVE-2024-0406HIGHCVSS 7.8v3.02024-04-06
CVE-2024-0406 [HIGH] CWE-22 CVE-2024-0406: A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specia
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
nvd
CVE-2023-48795MEDIUMCVSS 5.9PoCv3.0v4.02023-12-18
CVE-2023-48795 [MEDIUM] CWE-354 CVE-2023-48795: The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other pr
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgr
nvd
CVE-2023-4958MEDIUMCVSS 6.1v3.0v4.02023-12-12
CVE-2023-4958 [MEDIUM] CWE-1021 CVE-2023-4958: In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers w
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP headers were missing, allowing an attacker to exploit this with a clickjacking attack. An attacker could exploit this by convincing a valid RHACS user to visit an attacker-controlled web page, that deceptively points to valid RHACS endpoints, hijacking the user
nvd
CVE-2023-44487HIGHCVSS 7.5KEVPoCv3.0v4.02023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2022-1902HIGHCVSS 8.8v3.68v3.69+1 more2022-09-01
CVE-2022-1902 [HIGH] CWE-497 CVE-2022-1902: A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users to retrieve Notifiers from the GraphQL API, revealing secrets that can escalate their privileges.
nvd