BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2022
CVE-2022-29526High confidence

When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible

Unknown · Unknown

5.3MediumCVSS 3.1
Recommended action
Within 7 days

Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.

Patch available
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityMediumOperational priority:High, raised one band.upgradedsince 3 Aug 2024

Evidence used

  • No CISA KEV confirmation is currently recorded.
  • A structured source references public exploit or proof-of-concept material.
  • The selected CVSS metric records a network-reachable, unauthenticated path with no user interaction.
  • EPSS is 2.95% for the current model date.

Compensating controls

  • Validate the affected product branch and deploy the verified fixed release.
  • Restrict the affected network interface to trusted sources where business-safe.
  • Increase monitoring for the attack path and post-exploitation behaviour described in the report.

Verification

  1. Confirm that the asset runs Unknown Unknown and falls inside the recorded affected range.
  2. Verify the installed build against the product-specific fixed version after deployment.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 30 daysRemediation target: Within 180 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Distribution package intelligence

Release-specific package status

Alpine findings are scoped to the named distribution, release and source package. An absent finding does not mean a package is unaffected.

3 package states
Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Distribution releaseSource packageVendor stateFixed versionEvidence
Alpine v3.23v3.23 · communitydockerVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.20.10.16-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.22v3.22 · communitydockerVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.20.10.16-r0Alpine Security Database ↗Source updated 11 Sep 2026
Alpine v3.21v3.21 · communitydockerVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.20.10.16-r0Alpine Security Database ↗Source updated 19 Aug 2026
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

1 current
CVE-2022-29526 · CSAF 2.0 · revision 3 · finalRed Hat Product Securitygolang: syscall: faccessat checks wrong group
44 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • jenkins-operator-container as a component of OpenShift Developer Tools and Services
  • servicemesh-grafana as a component of OpenShift Service Mesh 2.0
  • servicemesh-grafana-prometheus as a component of OpenShift Service Mesh 2.0
  • servicemesh-grafana.src as a component of OpenShift Service Mesh 2.0
  • servicemesh-operator as a component of OpenShift Service Mesh 2.0
  • servicemesh-operator.src as a component of OpenShift Service Mesh 2.0
  • servicemesh-prometheus as a component of OpenShift Service Mesh 2.0
  • servicemesh-prometheus.src as a component of OpenShift Service Mesh 2.0
  • 3scale-apicast-operator-bundle-container as a component of Red Hat 3scale API Management Platform 2
  • rhacm2/agent-service-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
  • rhacm2/assisted-installer-agent-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
  • rhacm2/cert-policy-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2
Summary
A flaw was found in the syscall.Faccessat function when calling a process by checking the group. This flaw allows an attacker to check the process group permissions rather than a member of the file's group, affecting system availability.
Remediation
For OpenShift Container Platform 4.10 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.10/release_notes/ocp-4-10-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.10/updating/updating-cluster-cli.html
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2022-6106

No EUVD known-exploited evidence

ENISA has published the identifier mapping but no EUVD description has been stored yet.

EUVD state
Present in the current official mapping
Known exploitation
Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
ENISA score
Not supplied in the stored EUVD record
Advisory evidence
No linked advisory details stored yet
Recommended actionWithin 7 days

Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.

Patch available
01

What, why and how

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

What

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

Why

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

What

Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

Why

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

How

An attacker operating through a network path may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
No confirmed evidence

No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Reference recorded

A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.

Likely attack path
a network path → Improper Privilege Management → cause the confidentiality, integrity or availability impact described by the vendor
Attack surface
Network
Privileges required
None: unauthenticated exploitation is possible
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-269 ↗

CWE-269: Improper Privilege Management. The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVNetworkAttack vector: The vulnerable component can be reached over a network.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRNonePrivileges required: The attacker does not need an account or existing privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CLowConfidentiality impact: A successful attack can cause a limited loss.INoneIntegrity impact: No direct loss is represented by this metric.ANoneAvailability impact: No direct loss is represented by this metric.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
NetworkUnauthenticatedCWE-269Public exploit reference
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

BSI · German · WID-SEC-2024-0794Dell ECS: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.

Official advisory ↗
BSI · German · WID-SEC-2023-2229Splunk Splunk Enterprise: Mehrere Schwachstellen

Ein entfernter, authentifizierter Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise ausnutzen, um beliebigen Code auszuführen, einen 'Denial of Service'-Zustand zu verursachen, seine Privilegien zu erweitern und weitere, nicht spezifizierte Auswirkungen zu verursachen.

Official advisory ↗
BSI · German · WID-SEC-2023-1424Xerox FreeFlow Print Server für Solaris: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Xerox FreeFlow Print Server ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität des Systems zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2022-1461IBM Spectrum Protect: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM Spectrum Protect ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, einen Denial of Service Zustand herbeizuführen oder Sicherheitsvorkehrungen zu umgehen.

Official advisory ↗
BSI · German · WID-SEC-2023-1350Splunk Splunk Enterprise: Mehrere Schwachstellen in Komponenten von Drittanbietern

Ein Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise in diversen Komponenten von Drittanbietern ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.

Official advisory ↗
BSI · German · WID-SEC-2023-0204Red Hat OpenShift: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um beliebigen Programmcode auszuführen, Dateien zu manipulieren, einen Denial of Service Zustand herbeizuführen oder Sicherheitsvorkehrungen zu umgehen.

Official advisory ↗
BSI · German · WID-SEC-2022-2339IBM DB2: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in IBM DB2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data ausnutzen, um die Vertraulichkeit, Verfügbarkeit und Integrität zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2022-0491Red Hat Advanced Cluster Management: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Advanced Cluster Management ausnutzen, um Daten zu manipulieren, einen Denial of Service zu verursachen oder Informationen offenzulagen.

Official advisory ↗
Cyber Security Agency of Singapore · English · CSA-SB-20220629Security Bulletin 29 Jun 2022

The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 29 Jun 2022, published on 29 June 2022. Open the linked bulletin for the product, severity and reference information published in that issue.

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0339Multiples vulnérabilités dans les produits VMware

yAdvisories/0/37287 Bulletin de sécurité VMware 37288 du 20 mars 2026 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37288 Référence CVE CVE-2022-1705 https://www.cve.org/CVERecord?id=CVE-2022-1705 Référence CVE CVE-2022-1962 https://www.cve.org/CVERecord?id=CVE-2022-1962 Référence CVE CVE-2022-27664 https://www.cve.org/CVERecord?id=CVE-2022-27664 Référence CVE CVE-2022-28131 https://www.cve.org/CVERecord?id=CVE-2022-28131 Référence CVE CVE-2022-2879 https://www.cve.org/CVERecord?id=CVE-2022-2879 Référence CVE CVE-2022-2880 https://www.cve.org/CVERecord?id=CVE-2022-2880 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2022-29804 https://www.cve.org/CVERecord?id=CVE-2022-29804 Référence CVE CVE-2022-30580 https://www.cve.org/CVERecord?id=CVE-2022-30580 Référence CVE CVE-2022-30629 https://www.cve.org/CVERecord?id=CVE-2022-30629 Référence CVE CVE-2022-30630 https://www.cve.org/CVERecord?id=CVE-2022-30630 Référence CVE CVE-2022-30631 https://www.cve.org/CVERecord?id=CVE-2022-30631 Référence CVE CVE-2022-30632 https://www.cve.org/CVERecord?id=CVE-2022-30632 Référence CVE CVE-2022-30633 https://www.cve.org/CVERecord?id=CVE-2022-30633 Référence CVE CVE-2022-30634 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0326Multiples vulnérabilités dans les produits VMware

ord?id=CVE-2022-25836 Référence CVE CVE-2022-25837 https://www.cve.org/CVERecord?id=CVE-2022-25837 Référence CVE CVE-2022-26047 https://www.cve.org/CVERecord?id=CVE-2022-26047 Référence CVE CVE-2022-27635 https://www.cve.org/CVERecord?id=CVE-2022-27635 Référence CVE CVE-2022-27943 https://www.cve.org/CVERecord?id=CVE-2022-27943 Référence CVE CVE-2022-2795 https://www.cve.org/CVERecord?id=CVE-2022-2795 Référence CVE CVE-2022-28667 https://www.cve.org/CVERecord?id=CVE-2022-28667 Référence CVE CVE-2022-28693 https://www.cve.org/CVERecord?id=CVE-2022-28693 Référence CVE CVE-2022-29217 https://www.cve.org/CVERecord?id=CVE-2022-29217 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2022-2961 https://www.cve.org/CVERecord?id=CVE-2022-2961 Référence CVE CVE-2022-3114 https://www.cve.org/CVERecord?id=CVE-2022-3114 Référence CVE CVE-2022-3219 https://www.cve.org/CVERecord?id=CVE-2022-3219 Référence CVE CVE-2022-3238 https://www.cve.org/CVERecord?id=CVE-2022-3238 Référence CVE CVE-2022-3523 https://www.cve.org/CVERecord?id=CVE-2022-3523 Référence CVE CVE-2022-36087 https://www.cve.org/CVERecord?id=CVE-2022-36087 Référence CVE CVE-2022-36351 https://www.cve.org/CVERecord?id=CVE-2022-36351 Référence CVE CVE-2022-37341 https://www.cve.org/CVERecord?id=CVE-2022-3

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0316Multiples vulnérabilités dans les produits VMware

ord?id=CVE-2022-25836 Référence CVE CVE-2022-25837 https://www.cve.org/CVERecord?id=CVE-2022-25837 Référence CVE CVE-2022-26047 https://www.cve.org/CVERecord?id=CVE-2022-26047 Référence CVE CVE-2022-27635 https://www.cve.org/CVERecord?id=CVE-2022-27635 Référence CVE CVE-2022-27943 https://www.cve.org/CVERecord?id=CVE-2022-27943 Référence CVE CVE-2022-2795 https://www.cve.org/CVERecord?id=CVE-2022-2795 Référence CVE CVE-2022-28667 https://www.cve.org/CVERecord?id=CVE-2022-28667 Référence CVE CVE-2022-28693 https://www.cve.org/CVERecord?id=CVE-2022-28693 Référence CVE CVE-2022-29217 https://www.cve.org/CVERecord?id=CVE-2022-29217 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2022-2961 https://www.cve.org/CVERecord?id=CVE-2022-2961 Référence CVE CVE-2022-3114 https://www.cve.org/CVERecord?id=CVE-2022-3114 Référence CVE CVE-2022-3219 https://www.cve.org/CVERecord?id=CVE-2022-3219 Référence CVE CVE-2022-3238 https://www.cve.org/CVERecord?id=CVE-2022-3238 Référence CVE CVE-2022-3523 https://www.cve.org/CVERecord?id=CVE-2022-3523 Référence CVE CVE-2022-36087 https://www.cve.org/CVERecord?id=CVE-2022-36087 Référence CVE CVE-2022-36351 https://www.cve.org/CVERecord?id=CVE-2022-36351 Référence CVE CVE-2022-37341 https://www.cve.org/CVERecord?id=CVE-2022-3

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0218Multiples vulnérabilités dans les produits VMware

d?id=CVE-2022-27775 Référence CVE CVE-2022-27776 https://www.cve.org/CVERecord?id=CVE-2022-27776 Référence CVE CVE-2022-27781 https://www.cve.org/CVERecord?id=CVE-2022-27781 Référence CVE CVE-2022-27782 https://www.cve.org/CVERecord?id=CVE-2022-27782 Référence CVE CVE-2022-28321 https://www.cve.org/CVERecord?id=CVE-2022-28321 Référence CVE CVE-2022-28391 https://www.cve.org/CVERecord?id=CVE-2022-28391 Référence CVE CVE-2022-28805 https://www.cve.org/CVERecord?id=CVE-2022-28805 Référence CVE CVE-2022-29155 https://www.cve.org/CVERecord?id=CVE-2022-29155 Référence CVE CVE-2022-29458 https://www.cve.org/CVERecord?id=CVE-2022-29458 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2022-2953 https://www.cve.org/CVERecord?id=CVE-2022-2953 Référence CVE CVE-2022-29824 https://www.cve.org/CVERecord?id=CVE-2022-29824 Référence CVE CVE-2022-3219 https://www.cve.org/CVERecord?id=CVE-2022-3219 Référence CVE CVE-2022-32205 https://www.cve.org/CVERecord?id=CVE-2022-32205 Référence CVE CVE-2022-32206 https://www.cve.org/CVERecord?id=CVE-2022-32206 Référence CVE CVE-2022-32207 https://www.cve.org/CVERecord?id=CVE-2022-32207 Référence CVE CVE-2022-32208 https://www.cve.org/CVERecord?id=CVE-2022-32208 Référence CVE CVE-2022-32221 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0199Multiples vulnérabilités dans les produits VMware

ecord?id=CVE-2022-28327 Référence CVE CVE-2022-28391 https://www.cve.org/CVERecord?id=CVE-2022-28391 Référence CVE CVE-2022-2879 https://www.cve.org/CVERecord?id=CVE-2022-2879 Référence CVE CVE-2022-2880 https://www.cve.org/CVERecord?id=CVE-2022-2880 Référence CVE CVE-2022-28948 https://www.cve.org/CVERecord?id=CVE-2022-28948 Référence CVE CVE-2022-29189 https://www.cve.org/CVERecord?id=CVE-2022-29189 Référence CVE CVE-2022-29190 https://www.cve.org/CVERecord?id=CVE-2022-29190 Référence CVE CVE-2022-29222 https://www.cve.org/CVERecord?id=CVE-2022-29222 Référence CVE CVE-2022-29458 https://www.cve.org/CVERecord?id=CVE-2022-29458 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2022-29804 https://www.cve.org/CVERecord?id=CVE-2022-29804 Référence CVE CVE-2022-29946 https://www.cve.org/CVERecord?id=CVE-2022-29946 Référence CVE CVE-2022-30580 https://www.cve.org/CVERecord?id=CVE-2022-30580 Référence CVE CVE-2022-30629 https://www.cve.org/CVERecord?id=CVE-2022-30629 Référence CVE CVE-2022-30630 https://www.cve.org/CVERecord?id=CVE-2022-30630 Référence CVE CVE-2022-30631 https://www.cve.org/CVERecord?id=CVE-2022-30631 Référence CVE CVE-2022-30632 https://www.cve.org/CVERecord?id=CVE-2022-30632 Référence CVE CVE-2022-30633 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2026-AVI-0112Multiples vulnérabilités dans les produits VMware

-notification/-/external/content/SecurityAdvisories/0/36908 Bulletin de sécurité VMware 36909 du 02 février 2026 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36909 Bulletin de sécurité VMware 36910 du 02 février 2026 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36910 Bulletin de sécurité VMware 36911 du 02 février 2026 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36911 Référence CVE CVE-2016-1000027 https://www.cve.org/CVERecord?id=CVE-2016-1000027 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2022-49390 https://www.cve.org/CVERecord?id=CVE-2022-49390 Référence CVE CVE-2023-34231 https://www.cve.org/CVERecord?id=CVE-2023-34231 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2024-21510 https://www.cve.org/CVERecord?id=CVE-2024-21510 Référence CVE CVE-2024-23337 https://www.cve.org/CVERecord?id=CVE-2024-23337 Référence CVE CVE-2024-28180 https://www.cve.org/CVERecord?id=CVE-2024-28180 Référence CVE CVE-2024-38816 https://www.cve.org/CVERecord?id=CVE-2024-38816 Référence CVE CVE-2024-38819 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-1138Multiples vulnérabilités dans VMware Tanzu Platform

taillée se trouve à la fin de ce document. Risque Non spécifié par l'éditeur Systèmes affectés AI Services pour Tanzu Platform versions antérieures à 10.3.2 Résumé De multiples vulnérabilités ont été découvertes dans VMware Tanzu Platform. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. Solutions Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité VMware 36640 du 25 décembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36640 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2023-48022 https://www.cve.org/CVERecord?id=CVE-2023-48022 Référence CVE CVE-2024-45337 https://www.cve.org/CVERecord?id=CVE-2024-45337 Référence CVE CVE-2024-7254 https://www.cve.org/CVERecord?id=CVE-2024-7254 Référence CVE CVE-2025-0913 https://www.cve.org/CVERecord?id=CVE-2025-0913 Référence CVE CVE-2025-22869 https://www.cve.org/CVERecord?id=CVE-2025-22869 Référence CVE CVE-2025-22874 https://www.cve.org/CVERecord?id=CVE-2025-22874 Référence CVE CVE-2025-31133 https://www.cve.org/CVERecord?id=CVE-2025-31133 Référence CVE CVE-2025-34351 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-1129Multiples vulnérabilités dans les produits VMware

/external/content/SecurityAdvisories/0/36629 Bulletin de sécurité VMware DSA-2024-26 du 18 décembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36628 Bulletin de sécurité VMware DSA-2025-25 du 18 décembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36626 Bulletin de sécurité VMware DSA-2025-25 du 18 décembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36627 Référence CVE CVE-2020-7792 https://www.cve.org/CVERecord?id=CVE-2020-7792 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2023-48795 https://www.cve.org/CVERecord?id=CVE-2023-48795 Référence CVE CVE-2024-12905 https://www.cve.org/CVERecord?id=CVE-2024-12905 Référence CVE CVE-2024-21538 https://www.cve.org/CVERecord?id=CVE-2024-21538 Référence CVE CVE-2024-25126 https://www.cve.org/CVERecord?id=CVE-2024-25126 Référence CVE CVE-2024-25621 https://www.cve.org/CVERecord?id=CVE-2024-25621 Référence CVE CVE-2024-26141 https://www.cve.org/CVERecord?id=CVE-2024-26141 Référence CVE CVE-2024-26146 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-1036Multiples vulnérabilités dans les produits VMware

36534 du 24 novembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36534 Bulletin de sécurité VMware 36535 du 24 novembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36535 Bulletin de sécurité VMware 36536 du 24 novembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36536 Bulletin de sécurité VMware 36537 du 24 novembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36537 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2022-40897 https://www.cve.org/CVERecord?id=CVE-2022-40897 Référence CVE CVE-2023-27043 https://www.cve.org/CVERecord?id=CVE-2023-27043 Référence CVE CVE-2024-10976 https://www.cve.org/CVERecord?id=CVE-2024-10976 Référence CVE CVE-2024-10977 https://www.cve.org/CVERecord?id=CVE-2024-10977 Référence CVE CVE-2024-10978 https://www.cve.org/CVERecord?id=CVE-2024-10978 Référence CVE CVE-2024-10979 https://www.cve.org/CVERecord?id=CVE-2024-10979 Référence CVE CVE-2024-12254 https://www.cve.org/CVERecord?id=CVE-2024-12254 Référence CVE CVE-2024-12718 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0969Multiples vulnérabilités dans les produits VMware

rg/CVERecord?id=CVE-2022-2874 Référence CVE CVE-2022-2879 https://www.cve.org/CVERecord?id=CVE-2022-2879 Référence CVE CVE-2022-2880 https://www.cve.org/CVERecord?id=CVE-2022-2880 Référence CVE CVE-2022-28805 https://www.cve.org/CVERecord?id=CVE-2022-28805 Référence CVE CVE-2022-29217 https://www.cve.org/CVERecord?id=CVE-2022-29217 Référence CVE CVE-2022-2923 https://www.cve.org/CVERecord?id=CVE-2022-2923 Référence CVE CVE-2022-2928 https://www.cve.org/CVERecord?id=CVE-2022-2928 Référence CVE CVE-2022-2929 https://www.cve.org/CVERecord?id=CVE-2022-2929 Référence CVE CVE-2022-29458 https://www.cve.org/CVERecord?id=CVE-2022-29458 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2022-2953 https://www.cve.org/CVERecord?id=CVE-2022-2953 Référence CVE CVE-2022-2980 https://www.cve.org/CVERecord?id=CVE-2022-2980 Référence CVE CVE-2022-29804 https://www.cve.org/CVERecord?id=CVE-2022-29804 Référence CVE CVE-2022-29824 https://www.cve.org/CVERecord?id=CVE-2022-29824 Référence CVE CVE-2022-30580 https://www.cve.org/CVERecord?id=CVE-2022-30580 Référence CVE CVE-2022-30629 https://www.cve.org/CVERecord?id=CVE-2022-30629 Référence CVE CVE-2022-30630 https://www.cve.org/CVERecord?id=CVE-2022-30630 Référence CVE CVE-2022-30631 https://www.cve.org/CVERecord?id=CVE-

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0967Multiples vulnérabilités dans les produits VMware

d?id=CVE-2022-21426 Référence CVE CVE-2022-21434 https://www.cve.org/CVERecord?id=CVE-2022-21434 Référence CVE CVE-2022-21476 https://www.cve.org/CVERecord?id=CVE-2022-21476 Référence CVE CVE-2022-21540 https://www.cve.org/CVERecord?id=CVE-2022-21540 Référence CVE CVE-2022-21541 https://www.cve.org/CVERecord?id=CVE-2022-21541 Référence CVE CVE-2022-21619 https://www.cve.org/CVERecord?id=CVE-2022-21619 Référence CVE CVE-2022-21624 https://www.cve.org/CVERecord?id=CVE-2022-21624 Référence CVE CVE-2022-21626 https://www.cve.org/CVERecord?id=CVE-2022-21626 Référence CVE CVE-2022-21628 https://www.cve.org/CVERecord?id=CVE-2022-21628 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2022-3358 https://www.cve.org/CVERecord?id=CVE-2022-3358 Référence CVE CVE-2022-3602 https://www.cve.org/CVERecord?id=CVE-2022-3602 Référence CVE CVE-2022-3786 https://www.cve.org/CVERecord?id=CVE-2022-3786 Référence CVE CVE-2022-3996 https://www.cve.org/CVERecord?id=CVE-2022-3996 Référence CVE CVE-2022-40897 https://www.cve.org/CVERecord?id=CVE-2022-40897 Référence CVE CVE-2022-4203 https://www.cve.org/CVERecord?id=CVE-2022-4203 Référence CVE CVE-2022-4304 https://www.cve.org/CVERecord?id=CVE-2022-4304 Référence CVE CVE-2022-4450 https://www.cve.org/CVERecord?id=CVE-2022-4450

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0960Multiples vulnérabilités dans VMware Tanzu

36299 du 03 novembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36299 Bulletin de sécurité VMware 36300 du 04 novembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36300 Bulletin de sécurité VMware 36301 du 04 novembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36301 Bulletin de sécurité VMware 36302 du 04 novembre 2025 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36302 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2023-39325 https://www.cve.org/CVERecord?id=CVE-2023-39325 Référence CVE CVE-2023-3978 https://www.cve.org/CVERecord?id=CVE-2023-3978 Référence CVE CVE-2023-44487 https://www.cve.org/CVERecord?id=CVE-2023-44487 Référence CVE CVE-2023-45288 https://www.cve.org/CVERecord?id=CVE-2023-45288 Référence CVE CVE-2024-23337 https://www.cve.org/CVERecord?id=CVE-2024-23337 Référence CVE CVE-2024-24786 https://www.cve.org/CVERecord?id=CVE-2024-24786 Référence CVE CVE-2024-45336 https://www.cve.org/CVERecord?id=CVE-2024-45336 Référence CVE CVE-2024-45337 https://www.cve.org/CVERecord?id=CV

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0622Multiples vulnérabilités dans les produits VMware

ecord?id=CVE-2022-27780 Référence CVE CVE-2022-27781 https://www.cve.org/CVERecord?id=CVE-2022-27781 Référence CVE CVE-2022-27782 https://www.cve.org/CVERecord?id=CVE-2022-27782 Référence CVE CVE-2022-28131 https://www.cve.org/CVERecord?id=CVE-2022-28131 Référence CVE CVE-2022-28327 https://www.cve.org/CVERecord?id=CVE-2022-28327 Référence CVE CVE-2022-2879 https://www.cve.org/CVERecord?id=CVE-2022-2879 Référence CVE CVE-2022-2880 https://www.cve.org/CVERecord?id=CVE-2022-2880 Référence CVE CVE-2022-28948 https://www.cve.org/CVERecord?id=CVE-2022-28948 Référence CVE CVE-2022-29173 https://www.cve.org/CVERecord?id=CVE-2022-29173 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2022-29804 https://www.cve.org/CVERecord?id=CVE-2022-29804 Référence CVE CVE-2022-30580 https://www.cve.org/CVERecord?id=CVE-2022-30580 Référence CVE CVE-2022-30629 https://www.cve.org/CVERecord?id=CVE-2022-30629 Référence CVE CVE-2022-30630 https://www.cve.org/CVERecord?id=CVE-2022-30630 Référence CVE CVE-2022-30631 https://www.cve.org/CVERecord?id=CVE-2022-30631 Référence CVE CVE-2022-30632 https://www.cve.org/CVERecord?id=CVE-2022-30632 Référence CVE CVE-2022-30633 https://www.cve.org/CVERecord?id=CVE-2022-30633 Référence CVE CVE-2022-30634 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0524Multiples vulnérabilités dans VMware Tanzu

VERecord?id=CVE-2022-1941 Référence CVE CVE-2022-1962 https://www.cve.org/CVERecord?id=CVE-2022-1962 Référence CVE CVE-2022-25942 https://www.cve.org/CVERecord?id=CVE-2022-25942 Référence CVE CVE-2022-25972 https://www.cve.org/CVERecord?id=CVE-2022-25972 Référence CVE CVE-2022-26061 https://www.cve.org/CVERecord?id=CVE-2022-26061 Référence CVE CVE-2022-27664 https://www.cve.org/CVERecord?id=CVE-2022-27664 Référence CVE CVE-2022-28131 https://www.cve.org/CVERecord?id=CVE-2022-28131 Référence CVE CVE-2022-2879 https://www.cve.org/CVERecord?id=CVE-2022-2879 Référence CVE CVE-2022-2880 https://www.cve.org/CVERecord?id=CVE-2022-2880 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2022-30045 https://www.cve.org/CVERecord?id=CVE-2022-30045 Référence CVE CVE-2022-30580 https://www.cve.org/CVERecord?id=CVE-2022-30580 Référence CVE CVE-2022-30629 https://www.cve.org/CVERecord?id=CVE-2022-30629 Référence CVE CVE-2022-30630 https://www.cve.org/CVERecord?id=CVE-2022-30630 Référence CVE CVE-2022-30631 https://www.cve.org/CVERecord?id=CVE-2022-30631 Référence CVE CVE-2022-30632 https://www.cve.org/CVERecord?id=CVE-2022-30632 Référence CVE CVE-2022-30633 https://www.cve.org/CVERecord?id=CVE-2022-30633 Référence CVE CVE-2022-30635 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0701Multiples vulnérabilités dans Splunk

ecord?id=CVE-2022-27778 Référence CVE CVE-2022-27779 https://www.cve.org/CVERecord?id=CVE-2022-27779 Référence CVE CVE-2022-27780 https://www.cve.org/CVERecord?id=CVE-2022-27780 Référence CVE CVE-2022-27781 https://www.cve.org/CVERecord?id=CVE-2022-27781 Référence CVE CVE-2022-27782 https://www.cve.org/CVERecord?id=CVE-2022-27782 Référence CVE CVE-2022-28131 https://www.cve.org/CVERecord?id=CVE-2022-28131 Référence CVE CVE-2022-28327 https://www.cve.org/CVERecord?id=CVE-2022-28327 Référence CVE CVE-2022-2879 https://www.cve.org/CVERecord?id=CVE-2022-2879 Référence CVE CVE-2022-2880 https://www.cve.org/CVERecord?id=CVE-2022-2880 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2022-29804 https://www.cve.org/CVERecord?id=CVE-2022-29804 Référence CVE CVE-2022-30115 https://www.cve.org/CVERecord?id=CVE-2022-30115 Référence CVE CVE-2022-30580 https://www.cve.org/CVERecord?id=CVE-2022-30580 Référence CVE CVE-2022-30629 https://www.cve.org/CVERecord?id=CVE-2022-30629 Référence CVE CVE-2022-30630 https://www.cve.org/CVERecord?id=CVE-2022-30630 Référence CVE CVE-2022-30631 https://www.cve.org/CVERecord?id=CVE-2022-30631 Référence CVE CVE-2022-30632 https://www.cve.org/CVERecord?id=CVE-2022-30632 Référence CVE CVE-2022-30633 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0428Multiples vulnérabilités dans les produits Splunk

ecord?id=CVE-2022-27778 Référence CVE CVE-2022-27779 https://www.cve.org/CVERecord?id=CVE-2022-27779 Référence CVE CVE-2022-27780 https://www.cve.org/CVERecord?id=CVE-2022-27780 Référence CVE CVE-2022-27781 https://www.cve.org/CVERecord?id=CVE-2022-27781 Référence CVE CVE-2022-27782 https://www.cve.org/CVERecord?id=CVE-2022-27782 Référence CVE CVE-2022-28131 https://www.cve.org/CVERecord?id=CVE-2022-28131 Référence CVE CVE-2022-28327 https://www.cve.org/CVERecord?id=CVE-2022-28327 Référence CVE CVE-2022-2879 https://www.cve.org/CVERecord?id=CVE-2022-2879 Référence CVE CVE-2022-2880 https://www.cve.org/CVERecord?id=CVE-2022-2880 Référence CVE CVE-2022-29526 https://www.cve.org/CVERecord?id=CVE-2022-29526 Référence CVE CVE-2022-29804 https://www.cve.org/CVERecord?id=CVE-2022-29804 Référence CVE CVE-2022-30115 https://www.cve.org/CVERecord?id=CVE-2022-30115 Référence CVE CVE-2022-30580 https://www.cve.org/CVERecord?id=CVE-2022-30580 Référence CVE CVE-2022-30629 https://www.cve.org/CVERecord?id=CVE-2022-30629 Référence CVE CVE-2022-30630 https://www.cve.org/CVERecord?id=CVE-2022-30630 Référence CVE CVE-2022-30631 https://www.cve.org/CVERecord?id=CVE-2022-30631 Référence CVE CVE-2022-30632 https://www.cve.org/CVERecord?id=CVE-2022-30632 Référence CVE CVE-2022-30633 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0282Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM . Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, un déni de service, une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-723Multiples vulnérabilités dans IBM MQ

De multiples vulnérabilités ont été découvertes dans IBM MQ Operator et IBM MQ Advanced. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-1069Multiples vulnérabilités dans les produits IBM

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2022-012390The Go Project の Go 他複数ベンダの製品における権限管理に関する脆弱性

The Go Project の Go 他複数ベンダの製品には、権限管理に関する脆弱性が存在します。

Official advisory ↗
NCSC-NL · Dutch · NCSC-2024-0339Kwetsbaarheden verholpen in Microsoft Mariner

De kwetsbaarheden betreffen oudere kwetsbaarheden in diverse subcomponenten van de distro, zoals Python, Emacs, Qemu, Django, Curl, wget etc. welke in de nieuwe versie zijn verholpen.

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
Fixed
Action
For OpenShift Container Platform 4.10 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.10/release_notes/ocp-4-10-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.10/updating/updating-cluster-cli.html
Workaround
No verified workaround is recorded. If business-safe, reduce exposure to the affected interface and allow only trusted sources until authoritative guidance is available.
04

Evidence and provenance

Published 22 Jun 2022 · Last source change 3 Aug 2024, 06:26 UTC · CWE-269 · Improper Privilege Management

CVE recordCVE.org · 5.1
CVSS sourceNIST NVD
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2022-6106
Product sourceVendor CSAF · Red Hat Product Security
Remediation sourceVendor CSAF · Red Hat Product Security
CWE sourceNIST NVD
NVD statusNVD modified after enrichment

Missing structured fields: affected product. Missing data is not evidence of low risk; review the primary advisory.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Affected versionsThe structured affected or fixed version information changed.
    Before
    n/a · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    n/a · Fixed: For OpenShift Container Platform 4.10 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.10/release_notes/ocp-4-10-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.10/updating/updating-cluster-cli.html
    Red Hat Product Security ↗
  2. Affected versionsThe structured affected or fixed version information changed.
    Before
    jenkins-operator-container as a component of OpenShift Developer Tools and Services; servicemesh-grafana as a component of OpenShift Service Mesh 2.0; servicemesh-grafana-prometheus as a component of OpenShift Service Mesh 2.0; servicemesh-grafana.src as a component of OpenShift Service Mesh 2.0; servicemesh-operator as a component of OpenShift Service Mesh 2.0; servicemesh-operator.src as a component of OpenShift Service Mesh 2.0; servicemesh-prometheus as a component of OpenShift Service Mesh 2.0; servicemesh-prometheus.src as a component of OpenShift Service Mesh 2.0; 3scale-apicast-operator-bundle-container as a component of Red Hat 3scale API Management Platform 2; rhacm2/agent-service-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/assisted-installer-agent-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/cert-policy-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/cluster-curator-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/governance-policy-propagator-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/governance-policy-spec-sync-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/iam-policy-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/insights-client-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multicloud-manager-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multicluster-operators-application-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multicluster-operators-channel-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multicluster-operators-placementrule-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multicluster-operators-subscription-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multiclusterhub-repo-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multiclusterhub-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/observatorium-rhel8-operator as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/prometheus-alertmanager-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/rcm-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/registration-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; and 14 more · Fixed: cri-o-0:1.23.3-11.rhaos4.10.gitddf4b1a.1.el7.src as a component of Red Hat OpenShift Container Platform 4.10; cri-o-0:1.23.3-11.rhaos4.10.gitddf4b1a.1.el7.x86_64 as a component of Red Hat OpenShift Container Platform 4.10; cri-o-debuginfo-0:1.23.3-11.rhaos4.10.gitddf4b1a.1.el7.x86_64 as a component of Red Hat OpenShift Container Platform 4.10; openshift-0:4.10.0-202207192015.p0.g012e945.assembly.stream.el7.src as a component of Red Hat OpenShift Container Platform 4.10; openshift-clients-0:4.10.0-202207192015.p0.g45460a5.assembly.stream.el7.src as a component of Red Hat OpenShift Container Platform 4.10; openshift-clients-0:4.10.0-202207192015.p0.g45460a5.assembly.stream.el7.x86_64 as a component of Red Hat OpenShift Container Platform 4.10; openshift-clients-redistributable-0:4.10.0-202207192015.p0.g45460a5.assembly.stream.el7.x86_64 as a component of Red Hat OpenShift Container Platform 4.10; openshift-hyperkube-0:4.10.0-202207192015.p0.g012e945.assembly.stream.el7.x86_64 as a component of Red Hat OpenShift Container Platform 4.10; container-native-virtualization/libguestfs-tools@sha256:4f0d48312d8fe02a17747d65ac644d3e1be2df3cb80a9d0c268acc6ad5b91680_amd64 as a component of CNV 4.12 for RHEL 8; servicemesh-operator-0:2.1.5-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1; servicemesh-operator-0:2.1.5-1.el8.s390x as a component of OpenShift Service Mesh 2.1; servicemesh-operator-0:2.1.5-1.el8.src as a component of OpenShift Service Mesh 2.1; servicemesh-operator-0:2.1.5-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1; servicemesh-prometheus-0:2.23.0-9.el8.ppc64le as a component of OpenShift Service Mesh 2.1; servicemesh-prometheus-0:2.23.0-9.el8.s390x as a component of OpenShift Service Mesh 2.1; servicemesh-prometheus-0:2.23.0-9.el8.src as a component of OpenShift Service Mesh 2.1; servicemesh-prometheus-0:2.23.0-9.el8.x86_64 as a component of OpenShift Service Mesh 2.1; openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8@sha256:209bb896d29d4e7d28a0db24b07fcd9e173895c4291d404859701dd632b96a77_amd64 as a component of OSSO 1.0 for RHEL 8; advanced-cluster-security/rhacs-docs-rhel8@sha256:a17be9f88785c32bb6ab598072bae369f392b80037500947af5cd3f174daafe4_amd64 as a component of RHACS 3.72 for RHEL 8; advanced-cluster-security/rhacs-main-rhel8@sha256:142aeebfd057b8bf0bcc949190887a2fbc5bf160aa38e7ed70baaccf4f1438c3_amd64 as a component of RHACS 3.72 for RHEL 8; advanced-cluster-security/rhacs-rhel8-operator@sha256:12012f57ce5f5a3198288b21761b046a0090335d36eb5a6425ab547b04a82790_amd64 as a component of RHACS 3.72 for RHEL 8; advanced-cluster-security/rhacs-roxctl-rhel8@sha256:aa63f1ec9768107ef8ee6ca951589d3aba4abd0b6ebac17fd730360f06b25f36_amd64 as a component of RHACS 3.72 for RHEL 8; advanced-cluster-security/rhacs-scanner-rhel8@sha256:39076f8d7502262d78176bda06dfa5ed69bd43a42a5cdd431434bad30dd844ba_amd64 as a component of RHACS 3.72 for RHEL 8; advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:dd738be01a9a078d457e76cf54e2e88d112db971542a168cd4b016190cdf00e1_amd64 as a component of RHACS 3.72 for RHEL 8; rhmtc/openshift-migration-must-gather-rhel8@sha256:dcc13d7a3b2568686efd69c3c6c8f97f35fae4e496215ff3e8f941cb857ba6c2_amd64 as a component of 8Base-RHMTC-1.7; odf4/odf-csi-addons-sidecar-rhel8@sha256:0b9ecf62630f7ec27789275d02559675f58ed8efb9021f3af2031fde0a09fe6a_amd64 as a component of RHODF 4.11 for RHEL 8; odf4/odf-csi-addons-sidecar-rhel8@sha256:3ddf8e31f143ae15205e149921189fb3ea078064bfc1f059bfa0be4f6682a411_s390x as a component of RHODF 4.11 for RHEL 8; odf4/odf-csi-addons-sidecar-rhel8@sha256:6789e86605df10211bf7b0c51d89331164b8904002a84d846f02ae1f07b02de5_ppc64le as a component of RHODF 4.11 for RHEL 8; odf4/odf-topolvm-rhel8@sha256:1240938e119303864ba4b6ad342beec13cced941a7ddb08f6003afebead9e88f_s390x as a component of RHODF 4.11 for RHEL 8; odf4/odf-topolvm-rhel8@sha256:175337b3cba8447d0e8a05585faf4609cab47c4bf53be9bf6a2df05b8fa80ffa_ppc64le as a component of RHODF 4.11 for RHEL 8; and 84 more
    After
    jenkins-operator-container as a component of OpenShift Developer Tools and Services; servicemesh-grafana as a component of OpenShift Service Mesh 2.0; servicemesh-grafana-prometheus as a component of OpenShift Service Mesh 2.0; servicemesh-grafana.src as a component of OpenShift Service Mesh 2.0; servicemesh-operator as a component of OpenShift Service Mesh 2.0; servicemesh-operator.src as a component of OpenShift Service Mesh 2.0; servicemesh-prometheus as a component of OpenShift Service Mesh 2.0; servicemesh-prometheus.src as a component of OpenShift Service Mesh 2.0; 3scale-apicast-operator-bundle-container as a component of Red Hat 3scale API Management Platform 2; rhacm2/agent-service-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/assisted-installer-agent-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/cert-policy-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/cluster-curator-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/clusterlifecycle-state-metrics-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/governance-policy-propagator-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/governance-policy-spec-sync-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/iam-policy-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/insights-client-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/klusterlet-addon-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multicloud-manager-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multicluster-operators-application-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multicluster-operators-channel-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multicluster-operators-placementrule-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multicluster-operators-subscription-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multiclusterhub-repo-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/multiclusterhub-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/observatorium-rhel8-operator as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/prometheus-alertmanager-rhel9 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/rcm-controller-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; rhacm2/registration-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes 2; and 14 more · Fixed: cri-o-0:1.23.3-11.rhaos4.10.gitddf4b1a.1.el7.src as a component of Red Hat OpenShift Container Platform 4.10; cri-o-0:1.23.3-11.rhaos4.10.gitddf4b1a.1.el7.x86_64 as a component of Red Hat OpenShift Container Platform 4.10; cri-o-debuginfo-0:1.23.3-11.rhaos4.10.gitddf4b1a.1.el7.x86_64 as a component of Red Hat OpenShift Container Platform 4.10; openshift-0:4.10.0-202207192015.p0.g012e945.assembly.stream.el7.src as a component of Red Hat OpenShift Container Platform 4.10; openshift-clients-0:4.10.0-202207192015.p0.g45460a5.assembly.stream.el7.src as a component of Red Hat OpenShift Container Platform 4.10; openshift-clients-0:4.10.0-202207192015.p0.g45460a5.assembly.stream.el7.x86_64 as a component of Red Hat OpenShift Container Platform 4.10; openshift-clients-redistributable-0:4.10.0-202207192015.p0.g45460a5.assembly.stream.el7.x86_64 as a component of Red Hat OpenShift Container Platform 4.10; openshift-hyperkube-0:4.10.0-202207192015.p0.g012e945.assembly.stream.el7.x86_64 as a component of Red Hat OpenShift Container Platform 4.10; container-native-virtualization/libguestfs-tools@sha256:4f0d48312d8fe02a17747d65ac644d3e1be2df3cb80a9d0c268acc6ad5b91680_amd64 as a component of CNV 4.12 for RHEL 8; servicemesh-operator-0:2.1.5-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1; servicemesh-operator-0:2.1.5-1.el8.s390x as a component of OpenShift Service Mesh 2.1; servicemesh-operator-0:2.1.5-1.el8.src as a component of OpenShift Service Mesh 2.1; servicemesh-operator-0:2.1.5-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1; servicemesh-prometheus-0:2.23.0-9.el8.ppc64le as a component of OpenShift Service Mesh 2.1; servicemesh-prometheus-0:2.23.0-9.el8.s390x as a component of OpenShift Service Mesh 2.1; servicemesh-prometheus-0:2.23.0-9.el8.src as a component of OpenShift Service Mesh 2.1; servicemesh-prometheus-0:2.23.0-9.el8.x86_64 as a component of OpenShift Service Mesh 2.1; openshift-secondary-scheduler-operator/secondary-scheduler-operator-rhel8@sha256:209bb896d29d4e7d28a0db24b07fcd9e173895c4291d404859701dd632b96a77_amd64 as a component of OSSO 1.0 for RHEL 8; advanced-cluster-security/rhacs-docs-rhel8@sha256:a17be9f88785c32bb6ab598072bae369f392b80037500947af5cd3f174daafe4_amd64 as a component of RHACS 3.72 for RHEL 8; advanced-cluster-security/rhacs-main-rhel8@sha256:142aeebfd057b8bf0bcc949190887a2fbc5bf160aa38e7ed70baaccf4f1438c3_amd64 as a component of RHACS 3.72 for RHEL 8; advanced-cluster-security/rhacs-rhel8-operator@sha256:12012f57ce5f5a3198288b21761b046a0090335d36eb5a6425ab547b04a82790_amd64 as a component of RHACS 3.72 for RHEL 8; advanced-cluster-security/rhacs-roxctl-rhel8@sha256:aa63f1ec9768107ef8ee6ca951589d3aba4abd0b6ebac17fd730360f06b25f36_amd64 as a component of RHACS 3.72 for RHEL 8; advanced-cluster-security/rhacs-scanner-rhel8@sha256:39076f8d7502262d78176bda06dfa5ed69bd43a42a5cdd431434bad30dd844ba_amd64 as a component of RHACS 3.72 for RHEL 8; advanced-cluster-security/rhacs-scanner-slim-rhel8@sha256:dd738be01a9a078d457e76cf54e2e88d112db971542a168cd4b016190cdf00e1_amd64 as a component of RHACS 3.72 for RHEL 8; rhmtc/openshift-migration-must-gather-rhel8@sha256:dcc13d7a3b2568686efd69c3c6c8f97f35fae4e496215ff3e8f941cb857ba6c2_amd64 as a component of 8Base-RHMTC-1.7; odf4/odf-csi-addons-sidecar-rhel8@sha256:0b9ecf62630f7ec27789275d02559675f58ed8efb9021f3af2031fde0a09fe6a_amd64 as a component of RHODF 4.11 for RHEL 8; odf4/odf-csi-addons-sidecar-rhel8@sha256:3ddf8e31f143ae15205e149921189fb3ea078064bfc1f059bfa0be4f6682a411_s390x as a component of RHODF 4.11 for RHEL 8; odf4/odf-csi-addons-sidecar-rhel8@sha256:6789e86605df10211bf7b0c51d89331164b8904002a84d846f02ae1f07b02de5_ppc64le as a component of RHODF 4.11 for RHEL 8; odf4/odf-topolvm-rhel8@sha256:1240938e119303864ba4b6ad342beec13cced941a7ddb08f6003afebead9e88f_s390x as a component of RHODF 4.11 for RHEL 8; odf4/odf-topolvm-rhel8@sha256:175337b3cba8447d0e8a05585faf4609cab47c4bf53be9bf6a2df05b8fa80ffa_ppc64le as a component of RHODF 4.11 for RHEL 8; and 84 more
    Red Hat Product Security ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
CVE published
Fixed release or patch reference recorded
Fixed release recorded from official guidance
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2022-29526 · cve.blacktree.nl