Impact
A flaw in Red Hat Advanced Cluster Security for Kubernetes allows an authenticated user to submit GraphQL queries of arbitrary depth to the Central service. Because no depth limit is enforced, these deeply nested queries consume excessive CPU and memory resources, leading to a denial of service in the management plane.
Affected Systems
Affected installations are Red Hat Advanced Cluster Security for Kubernetes version 4.9 on EL 8, version 4.10 on EL 8, and version 4.11 on EL 9, as identified by the vendor through their errata listings. All installations running these specific versions are vulnerable.
Risk and Exploitability
The CVSS base score of 7.7 indicates a moderate to high severity. The EPSS score of < 1 % reflects a very low probability of exploitation under current conditions the vulnerability is not listed in CISA’s KEV catalog. An attacker must first obtain an authenticated API token; no known unauthenticated or remote code execution exploits are described. The likely attack vector is an authenticated user exploiting the API to submit a deep GraphQL query that exhausts Central’s resources, potentially disrupting Kubernetes cluster management for the organization.
OpenCVE Enrichment