drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mangelnde Rechteprüfung in Multicluster Engine for Kubernetes
| Name: |
Mangelnde Rechteprüfung in Multicluster Engine for Kubernetes |
|
| ID: |
RHSA-2025:0676 |
|
| Distribution: |
Red Hat |
|
| Plattformen: |
Red Hat multicluster engine for Kubernetes 2.5 for RHEL 9, Red Hat multicluster engine for Kubernetes 2.5 for RHEL 8 |
|
| Datum: |
Fr, 24. Januar 2025, 06:49 |
|
| Referenzen: |
https://bugzilla.redhat.com/show_bug.cgi?id=2331720
https://access.redhat.com/errata/RHSA-2025:0676
https://access.redhat.com/security/cve/CVE-2024-45337 |
|
| Applikationen: |
Multicluster Engine for Kubernetes |
|
Originalnachricht |
Multicluster Engine for Kubernetes 2.5.8 General Availability release images, which provide enhancements, bug fixes, and updated container images.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section.
Multicluster engine for Kubernetes v2.5.8 images
Multicluster engine for Kubernetes provides the foundational components that are necessary for the centralized management of multiple Kubernetes-based clusters across data centers, public clouds, and private clouds.
You can use the engine to create new Red Hat OpenShift Container Platform clusters or to bring existing Kubernetes-based clusters under management by importing them. After the clusters are managed, you can use the APIs that are provided by the engine to distribute configuration based on placement policy.
Security Fix(es):
* Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337)
This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.
CVE-2024-45337: Improper Authorization (CWE-285)
|
|
|
|