CVE-2022-2238
MEDIUMRed Hat Advanced Cluster Management for Kubernetes - Denial of Service via Search Filter Query Parsing
Title source: llmDescription
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific strings containing special characters that lead to crashing the pod and affects system availability while restarting.
References (2)
Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2101669
Vendor Advisory x_refsource_misc
https://access.redhat.com/security/cve/CVE-2022-2238
Scores
CVSS v3
6.5
EPSS
0.0072
EPSS Percentile
72.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-89
Status
published
Products (1)
redhat/advanced_cluster_management_for_kubernetes
2.0
Published
Sep 01, 2022
Tracked Since
Feb 18, 2026