Red Hat Advanced Cluster Security
cpe:2.3:a:redhat:advanced_cluster_security:*:*:*:*:*:*:*
- <= 3
A cross-site scripting (XSS) vulnerability has been identified in the Red Hat Advanced Cluster Security (RHACS) portal. This issue arises when the portal renders a table view, particularly on endpoints under '/main/configmanagement/*'. The front-end creates a DOM table element with the id 'pdf-table', which is filled with unsanitized data using innerHTML. An attacker with some control over the rendered data can exploit this vulnerability.
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
To reproduce this vulnerability, an authenticated user must create a RHACS policy or an OpenShift cluster role with a specially crafted name that includes unsanitized data. Once this data is rendered in the RHACS portal, the XSS vulnerability can be observed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.