CyberRota Analysis
AI-GeneratedA vulnerability in Red Hat Advanced Cluster Security for Kubernetes allows authenticated users to exploit the GraphQL API by sending deeply nested queries, leading to excessive resource consumption and potential denial of service for the management plane. Organizations utilizing RHACS should prioritize addressing this issue to protect their Kubernetes environments from service disruptions. Immediate action is recommended for teams managing sensitive workloads or relying heavily on the affected API.
Original NVD Description
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.