High severity7.8NVD Advisory· Published Jan 13, 2023· Updated Jun 17, 2026
CVE-2022-3841
CVE-2022-3841
Description
RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check, allowing unauthenticated users making requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:redhat:advanced_cluster_management_for_kubernetes:2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:advanced_cluster_management_for_kubernetes:2.0:*:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
1- access.redhat.com/security/cve/CVE-2022-3841nvdVendor Advisory
News mentions
0No linked articles in our index yet.