Advanced cluster management for kubernetes
This hub aggregates every CVE we track for Advanced cluster management for kubernetes, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Operating Systemson-prem
12
CVEs tracked
0
Critical
6
High
1
In CISA KEV
Severity distribution
HIGH6MEDIUM5LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
1
0
0
0
2
0
0
0
0
2024-092026-08
Latest CVEs
The 12 most recently published vulnerabilities affecting Advanced cluster management for kubernetes.
- CVE-2025-57851Mce: privilege escalation via excessive /etc/passwd permissions6.4
- CVE-2026-4740Rhacm: open cluster management (ocm): cross-cluster privilege escalation via improper kubernetes client certificate renewal validation8.2
- CVE-2025-14874Nodemailer: nodemailer: denial of service via crafted email address header7.5
- CVE-2025-6017Rhacm: users with clusterreader role can see credentials from managed-clusters5.5
- CVE-2023-44487The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.KEV7.5
- CVE-2022-3248Openshift api admission checks does not enforce "custom-host" permissions4.4
- CVE-2023-3027The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained values (instead of the policy apply a static manifest...7.8
- CVE-2022-3841RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes...7.8
- CVE-2022-2238A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend. This flaw allows an attacke...6.5
- CVE-2022-27191The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.7.5
- CVE-2020-25688A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in al...3.5
- CVE-2020-25655An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a s...5.7
Product normalization is registry-driven with AI assist and human review. How it works