Login
Newsletter
Werbung

Sicherheit: Mangelnde Rechteprüfung in Multicluster Engine for Kubernetes
Aktuelle Meldungen Distributionen
Name: Mangelnde Rechteprüfung in Multicluster Engine for Kubernetes
ID: RHSA-2025:0676
Distribution: Red Hat
Plattformen: Red Hat multicluster engine for Kubernetes 2.5 for RHEL 9, Red Hat multicluster engine for Kubernetes 2.5 for RHEL 8
Datum: Fr, 24. Januar 2025, 06:49
Referenzen: https://bugzilla.redhat.com/show_bug.cgi?id=2331720
https://access.redhat.com/errata/RHSA-2025:0676
https://access.redhat.com/security/cve/CVE-2024-45337
Applikationen: Multicluster Engine for Kubernetes

Originalnachricht

Multicluster Engine for Kubernetes 2.5.8 General Availability release images, 
which provide enhancements, bug fixes, and updated container images.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE links in the References section.

Multicluster engine for Kubernetes v2.5.8 images

Multicluster engine for Kubernetes provides the foundational components
that are necessary for the centralized management of multiple
Kubernetes-based clusters across data centers, public clouds, and private
clouds.

You can use the engine to create new Red Hat OpenShift Container Platform
clusters or to bring existing Kubernetes-based clusters under management by
importing them. After the clusters are managed, you can use the APIs that
are provided by the engine to distribute configuration based on placement
policy.

Security Fix(es):

* Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in
golang.org/x/crypto (CVE-2024-45337)

This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

CVE-2024-45337: Improper Authorization (CWE-285)
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung