First published: Wed Apr 28 2021(Updated: )
Red Hat Advanced Cluster Management for Kubernetes 2.0.10 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which resolve some security issues and bugs. See<br>the following Release Notes documentation, which will be updated shortly<br>for this release, for details about this<br>release:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.0/html/release_notes/" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.0/html/release_notes/</a> Security fixes: <br><li> nodejs-underscore: Arbitrary code execution via the template function (CVE-2021-23358)</li> For more details about the security issue, including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page(s) listed in the References section.<br>Bug fix:<br><li> RHACM 2.0.10 images (BZ #1940452)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Advanced Cluster Management |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:1448 is classified as moderate.
To fix RHSA-2021:1448, update to the latest version of Red Hat Advanced Cluster Management for Kubernetes.
RHSA-2021:1448 addresses multiple security vulnerabilities affecting Red Hat Advanced Cluster Management for Kubernetes related to authorization and privilege escalation.
No specific workaround is recommended for RHSA-2021:1448; applying the update is advised.
The RHSA-2021:1448 advisory was released on May 10, 2021.