First published: Tue May 04 2021(Updated: )
Red Hat Advanced Cluster Management for Kubernetes 2.2.3 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to<br>address common challenges that administrators and site reliability engineers<br>face as they work across a range of public and private cloud environments.<br>Clusters and applications are all visible and managed from a single console—with<br>security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs and security issues. See the<br>following Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.2/html/release_notes/" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.2/html/release_notes/</a> Security fixes:<br><li> nodejs-underscore: Arbitrary code execution via the template function (CVE-2021-23358)</li> <li> nodejs-netmask: improper input validation of octal input data (CVE-2021-28918)</li> <li> nodejs-glob-parent: Regular expression denial of service (CVE-2020-28469)</li> <li> nodejs-is-svg: ReDoS via malicious string (CVE-2021-28092)</li> <li> nodejs-netmask: incorrectly parses an IP address that has octal integer with invalid character (CVE-2021-29418)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>pages listed in the References section.<br>Bug fixes: <br><li> ACM UI is not escaping cluster names (BZ# 1936883)</li> <li> specify "folder:" for vsphere cluster creation result empty namespace ,no hive (BZ# 1943092)</li> <li> RHACM 2.2.3 images (BZ# 1949103)</li> <li> Applications won't create properly on native K8S cluster (BZ# 1951384)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Advanced Cluster Management |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2021:1499 is listed as critical.
To fix RHSA-2021:1499, upgrade Red Hat Advanced Cluster Management for Kubernetes to the latest version as recommended in the advisory.
RHSA-2021:1499 affects Red Hat Advanced Cluster Management for Kubernetes version 2.2.3.
RHSA-2021:1499 addresses multiple security vulnerabilities that could lead to unauthorized access and privilege escalation.
RHSA-2021:1499 was released on October 19, 2021.