Loading
RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check, allowing unauthenticated users making requests.
Use CWE-918, Redhat vendor hub and Advanced Cluster Management For Kubernetes product page to widen CVE-2022-3841 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-44487, CVE-2026-4740 and CVE-2023-3027 for nearby disclosures in the same product family.