RHSA-2021:2461: Moderate: Red Hat Advanced Cluster Management 2.2.4 security and bug fix update
Red Hat Advanced Cluster Management for Kubernetes 2.2.4 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site reliability<br>engineers face as they work across a range of public and private cloud environments.<br>Clusters and applications are all visible and managed from a single<br>console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs and security issues. See<br>the following Release Notes documentation, which will be updated shortly for<br>this release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.2/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.2/html/releasenotes/</a> Security fixes:<br><li> redisgraph-tls: redis: integer overflow when configurable limit for maximum supported bulk input size is too big on 32-bit platforms (CVE-2021-21309)</li> <li> console-header-container: nodejs-netmask: improper input validation of octal input data (CVE-2021-28092)</li> <li> console-container: nodejs-is-svg: ReDoS via malicious string (CVE-2021-28918)</li> Bug fixes: <br><li> RHACM 2.2.4 images (BZ# 1957254)</li> <li> Enabling observability for OpenShift Container Storage with RHACM 2.2 on OCP 4.7 (BZ#1950832)</li> <li> ACM Operator should support using the default route TLS (BZ# 1955270)</li> <li> The scrolling bar for search filter does not work properly (BZ# 1956852)</li> <li> Limits on Length of MultiClusterObservability Resource Name (BZ# 1959426)</li> <li> The proxy setup in install-config.yaml is not worked when IPI installing with RHACM (BZ# 1960181)</li> <li> Unable to make SSH connection to a Bitbucket server (BZ# 1966513)</li> <li> Observability Thanos store shard crashing - cannot unmarshall DNS message (BZ# 1967890)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:2461?
The severity of RHSA-2021:2461 is classified as important.
How do I fix RHSA-2021:2461?
To fix RHSA-2021:2461, update the Red Hat Advanced Cluster Management for Kubernetes to the latest version as recommended in the advisory.
What products are affected by RHSA-2021:2461?
RHSA-2021:2461 affects Red Hat Advanced Cluster Management for Kubernetes version 2.2.4.
What type of vulnerability is addressed in RHSA-2021:2461?
RHSA-2021:2461 addresses important security vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes.
When was RHSA-2021:2461 released?
RHSA-2021:2461 was released on August 31, 2021.