drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in Red Hat Advanced Cluster Management 2.9.2
Name: |
Zwei Probleme in Red Hat Advanced Cluster Management 2.9.2 |
|
ID: |
RHSA-2024:0298 |
|
Distribution: |
Red Hat |
|
Plattformen: |
Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8 |
|
Datum: |
Fr, 19. Januar 2024, 06:58 |
|
Referenzen: |
https://issues.redhat.com/browse/ACM-8966
https://access.redhat.com/security/cve/CVE-2023-49569
https://access.redhat.com/errata/RHSA-2024:0298
https://issues.redhat.com/browse/ACM-8857
https://bugzilla.redhat.com/show_bug.cgi?id=2258165
https://access.redhat.com/security/cve/CVE-2023-49568
https://issues.redhat.com/browse/ACM-9094
https://issues.redhat.com/browse/ACM-8456
https://bugzilla.redhat.com/show_bug.cgi?id=2258143 |
|
Applikationen: |
Red Hat Advanced Cluster Management 2.9.2 |
|
Originalnachricht |
Red Hat Advanced Cluster Management for Kubernetes 2.9.2 General Availability release images, which provide security updates and fix bugs.
Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section.
Red Hat Advanced Cluster Management for Kubernetes 2.9.2 images
Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in.
Jira issues addressed:
ACM-8456: 'Search' feature on logs page is not working ACM-8857: credentials restore file is executed after resources restore ACM-8966: oc get policy still returns NonCompliant 10 minutes after deleting the certificate and secret ACM-9094: Configuration Policy controller unexpectedly gets taken out of uninstall mode
Security fix(es): CVE-2023-49568 go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
CVE-2023-49568: Uncontrolled Resource Consumption (CWE-400) CVE-2023-49569: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
|
|
|
|