Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in Red Hat Advanced Cluster Management 2.9.2
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in Red Hat Advanced Cluster Management 2.9.2
ID: RHSA-2024:0298
Distribution: Red Hat
Plattformen: Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8
Datum: Fr, 19. Januar 2024, 06:58
Referenzen: https://issues.redhat.com/browse/ACM-8966
https://access.redhat.com/security/cve/CVE-2023-49569
https://access.redhat.com/errata/RHSA-2024:0298
https://issues.redhat.com/browse/ACM-8857
https://bugzilla.redhat.com/show_bug.cgi?id=2258165
https://access.redhat.com/security/cve/CVE-2023-49568
https://issues.redhat.com/browse/ACM-9094
https://issues.redhat.com/browse/ACM-8456
https://bugzilla.redhat.com/show_bug.cgi?id=2258143
Applikationen: Red Hat Advanced Cluster Management 2.9.2

Originalnachricht

Red Hat Advanced Cluster Management for Kubernetes 2.9.2 General
Availability release images, which provide security updates and fix bugs.

Red Hat Product Security has rated this update as having a security impact
of Critical. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE links in the References section.

Red Hat Advanced Cluster Management for Kubernetes 2.9.2 images

Red Hat Advanced Cluster Management for Kubernetes provides the
capabilities to address common challenges that administrators and site
reliability engineers face as they work across a range of public and
private cloud environments. Clusters and applications are all visible and
managed from a single console—with security policy built in.

Jira issues addressed:

ACM-8456: 'Search' feature on logs page is not working
ACM-8857: credentials restore file is executed after resources restore
ACM-8966: oc get policy still returns NonCompliant 10 minutes after deleting
the certificate and secret
ACM-9094: Configuration Policy controller unexpectedly gets taken out of
uninstall mode

Security fix(es):
CVE-2023-49568 go-git: Maliciously crafted Git server replies can cause DoS on
go-git clients
CVE-2023-49569 go-git: Maliciously crafted Git server replies can lead to path
traversal and RCE on go-git clients

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2023-49568: Uncontrolled Resource Consumption (CWE-400)
CVE-2023-49569: Improper Limitation of a Pathname to a Restricted Directory
('Path Traversal') (CWE-22)
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung