Impact
The flaw in acm-search-v2-api-rhel9 lets a user’s bearer token be improperly reused for all subsequent federated search requests after the cache is refreshed. This behavior permits an authenticated user to retrieve search results from remote hubs that belong to other users, thereby disclosing privileged data across tenant boundaries.
Affected Systems
Red Hat Advanced Cluster Management for Kubernetes version 2 (acm 2) on Red Enterprise Linux 9 is affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate level of severity, and the EPSS score of less than 1% suggests that active exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need to authenticate to the system and the ability to trigger the getFederationConfig cache refresh; this capacity is inferred from the description, not explicitly documented, and does not require elevated privileges beyond normal user access. Once the cache is stale, any authenticated user can request data from other tenants, exposing sensitive information.
OpenCVE Enrichment