CVE-2022-4975: Rhacs: cross-site scripting in portal
A cross-site scripting vulnerability is present in Red Hat Advanced Cluster Security (RHACS) portal. When rendering a table-view in the portal, (e.g. on any of the endpoints /main/configmanagement/), the front-end generates a DOM table-element (id="pdf-table"). This is then populated with unsanitized data using innerHTML. Since an attacker has some control over the data rendered, this makes it vulnerable to an XSS-attack.
Other sources
A flaw was found in the Red Hat Advanced Cluster Security (RHACS) portal. When rendering a table view in the portal, for example, on any of the /main/configmanagement/ endpoints, the front-end generates a DOM table-element (id="pdf-table"). This information is then populated with unsanitized data using innerHTML. An attacker with some control over the data rendered can trigger a cross-site scripting (XSS) vulnerability.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4975?
CVE-2022-4975 is classified as a cross-site scripting vulnerability that can lead to security risks in the Red Hat Advanced Cluster Security portal.
How do I fix CVE-2022-4975?
To mitigate CVE-2022-4975, ensure that you are running the latest patched version of Red Hat Advanced Cluster Security.
Which versions of Red Hat Advanced Cluster Security are affected by CVE-2022-4975?
CVE-2022-4975 affects specific versions of Red Hat Advanced Cluster Security but the exact versions are not detailed in the advisory.
What type of attack does CVE-2022-4975 enable?
CVE-2022-4975 enables cross-site scripting (XSS) attacks that could compromise user data or session information.
Where can I report incidents related to CVE-2022-4975?
Incidents related to CVE-2022-4975 should be reported through Red Hat's security channels or support team.