First published: Tue Sep 06 2022(Updated: )
Multicluster engine for Kubernetes 2.1 images<br>Multicluster engine for Kubernetes provides the foundational components<br>that are necessary for the centralized management of multiple<br>Kubernetes-based clusters across data centers, public clouds, and private<br>clouds.<br>You can use the engine to create new Red Hat OpenShift Container Platform<br>clusters or to bring existing Kubernetes-based clusters under management by<br>importing them. After the clusters are managed, you can use the APIs that<br>are provided by the engine to distribute configuration based on placement<br>policy.<br>Security fixes:<br><li> CVE-2022-31129 moment: inefficient parsing algorithm resulting in DoS</li> <li> CVE-2022-1705 golang: net/<a href="http:" target="_blank">http:</a> improper sanitization of Transfer-Encoding header</li> <li> CVE-2022-1962 golang: go/parser: stack exhaustion in all Parse* functions</li> <li> CVE-2022-28131 golang: encoding/xml: stack exhaustion in Decoder.Skip</li> <li> CVE-2022-30630 golang: io/fs: stack exhaustion in Glob</li> <li> CVE-2022-30631 golang: compress/gzip: stack exhaustion in Reader.Read</li> <li> CVE-2022-30632 golang: path/filepath: stack exhaustion in Glob</li> <li> CVE-2022-30633 golang: encoding/xml: stack exhaustion in Unmarshal</li> <li> CVE-2022-30635 golang: encoding/gob: stack exhaustion in Decoder.Decode</li> <li> CVE-2022-32148 golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working</li> <li> CVE-2022-30629 golang: crypto/tls: session tickets lack random ticket_age_add</li> Bug fixes:<br><li> MCE 2.1.0 Images (BZ# 2090907)</li> <li> cluster-proxy-agent not able to startup (BZ# 2109394)</li> <li> Create cluster button skips Infrastructure page, shows blank page (BZ# 2110713)</li> <li> AWS Icon sometimes doesn't show up in create cluster wizard (BZ# 2110734)</li> <li> Infrastructure descriptions in create cluster catalog should be consistent and clear (BZ# 2110811)</li> <li> The user with clusterset view permission should not able to update the namespace binding with the pencil icon on clusterset details page (BZ# 2111483)</li> <li> hypershift cluster creation -> not all agent labels are shown in the node pools screen (BZ# 2112326)</li> <li> CIM - SNO expansion, worker node status incorrect (BZ# 2114735)</li> <li> Wizard fields are not pre-filled after picking credentials (BZ# 2117163)</li> <li> ManagedClusterImageRegistry CR is wrong in pure MCE env</li>
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.