Impact
The vulnerability lies in the authentication middleware of search-v2-api, where any HTTP request containing an Upgrade: websocket header is treated as authenticated regardless of credentials. An attacker can craft a POST request to the /federated endpoint with this header, which lets them bypass authentication and retrieve federated search results from all configured remote hubs, exposing sensitive data. This flaw is categorized as CWE-287, an authentication bypass weakness.
Affected Systems
Red Hat Advanced Cluster Management for Kubernetes version 2 is affected. No further version granularity is specified beyond the component identifier cpe:/a:redhat:acm:2.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% suggests that the likelihood of exploitation is very low at this time. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, from an external network, where an attacker initiates the unauthorized request. Exploitation requires the ability to send HTTP requests to the /federated endpoint and includes no special privileges beyond network connectivity.
OpenCVE Enrichment