Redhat
Redhat Advanced Cluster Management FOR Kubernetes: vulnerabilidades y CVE
Redhat Advanced Cluster Management FOR Kubernetes tiene 24 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses15
Críticas1
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-66787 | Media (5.4) | 0.35% | — | 20 ago 2026 | A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A… |
| CVE-2026-66783 | Media (4.4) | 0.35% | — | 18 ago 2026 | A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner… |
| CVE-2026-75485 | Media (5.5) | 0.19% | — | 18 ago 2026 | A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize… |
| CVE-2026-73834 | Media (5.5) | 0.11% | — | 18 ago 2026 | A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator… |
| CVE-2026-66793 | Alta (8.8) | 0.81% | — | 18 ago 2026 | A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override… |
| CVE-2026-71846 | Media (6.5) | 0.16% | — | 12 ago 2026 | A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific… |
| CVE-2026-71845 | Alta (7.7) | 0.50% | — | 11 ago 2026 | A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog… |
| CVE-2026-71475 | Media (6.8) | 0.69% | — | 11 ago 2026 | A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the… |
| CVE-2026-71474 | Media (6.5) | 0.16% | — | 11 ago 2026 | A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on… |
| CVE-2026-10090 | Crítica (9) | 0.58% | — | 5 ago 2026 | A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub… |
| CVE-2026-17107 | Alta (8.5) | 0.57% | — | 24 jul 2026 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to… |
| CVE-2026-44495 | Alta (7.7) | 1.0% | — | 11 jun 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same… |
| CVE-2025-57851 | Media (6.7) | 0.11% | — | 8 abr 2026 | A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In… |
| CVE-2026-4740 | Alta (8.2) | 0.16% | — | 7 abr 2026 | A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator… |
| CVE-2025-14874 | Alta (7.5) | 0.56% | — | 18 dic 2025 | A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser. |
| CVE-2025-6017 | Media (5.5) | 0.14% | — | 2 jul 2025 | A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed… |
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2022-3248 | Alta (7.5) | 0.48% | — | 5 oct 2023 | A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied. |
| CVE-2023-3027 | Alta (7.8) | 0.20% | — | 5 jun 2023 | The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest on a managed cluster)… |
| CVE-2022-3841 | Alta (7.8) | 0.23% | — | 13 ene 2023 | RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker… |
| CVE-2022-2238 | Media (6.5) | 0.92% | — | 1 sept 2022 | A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacker to craft specific… |
| CVE-2022-27191 | Alta (7.5) | 3.9% | — | 18 mar 2022 | The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey. |
| CVE-2020-25688 | Baja (3.5) | 0.25% | — | 23 nov 2020 | A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using… |
| CVE-2020-25655 | Media (6.5) | 0.61% | — | 9 nov 2020 | An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 239Linux · 230