GHSA-wg82-w434-qwgqMediumCVSS 5.3
A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes...
🔗 CVE IDs covered (1)
📋 Description
A flaw was found in acm-search-v2-api-rhel9. When the getFederationConfig function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.
🔗 References (10)
- https://nvd.nist.gov/vuln/detail/CVE-2026-71468
- https://access.redhat.com/security/cve/CVE-2026-71468
- https://bugzilla.redhat.com/show_bug.cgi?id=2512147
- https://access.redhat.com/errata/RHSA-2026:60386
- https://access.redhat.com/errata/RHSA-2026:60389
- https://access.redhat.com/errata/RHSA-2026:60390
- https://access.redhat.com/errata/RHSA-2026:60387
- https://access.redhat.com/errata/RHSA-2026:60388
- https://access.redhat.com/errata/RHSA-2026:60391
- https://github.com/advisories/GHSA-wg82-w434-qwgq