CVE-2022-2238

MEDIUM

Red Hat Advanced Cluster Management for Kubernetes - Denial of Service via Search Filter Query Parsing

Title source: llm
STIX 2.1

Description

A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability while restarting.

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2101669
Vendor Advisory x_refsource_misc
https://access.redhat.com/security/cve/CVE-2022-2238

Scores

CVSS v3 6.5
EPSS 0.0072
EPSS Percentile 72.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-89
Status published
Products (1)
redhat/advanced_cluster_management_for_kubernetes 2.0
Published Sep 01, 2022
Tracked Since Feb 18, 2026