First published: Wed May 04 2022(Updated: )
Red Hat Advanced Cluster Management for Kubernetes 2.3.10 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs. See the following<br>Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.3/html/release_notes/" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.3/html/release_notes/</a> Security updates:<br><li> Follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor (CVE-2022-0155)</li> <li> Node-fetch: exposure of sensitive information to an unauthorized actor (CVE-2022-0235)</li> <li> Follow-redirects: Exposure of Sensitive Information via Authorization Header leak (CVE-2022-0536)</li> <li> Urijs: Authorization Bypass Through User-Controlled Key (CVE-2022-0613)</li> <li> Urijs: Leading white space bypasses protocol validation (CVE-2022-24723)</li> <li> Nconf: Prototype pollution in memory store (CVE-2022-21803)</li> <li> Moment.js: Path traversal in moment.locale (CVE-2022-24785)</li> Bug fixes:<br><li> RHACM 2.3.10 images</li>
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:1715 is classified as important.
To fix RHSA-2022:1715, update the affected Red Hat Advanced Cluster Management for Kubernetes packages to the latest version available.
RHSA-2022:1715 affects Red Hat Advanced Cluster Management for Kubernetes version 2.3.10.
There are no specific workarounds for RHSA-2022:1715; updating the software is the recommended action.
RHSA-2022:1715 impacts systems running Red Hat Advanced Cluster Management for Kubernetes 2.3.10.