First published: Tue Nov 01 2022(Updated: )
Red Hat Advanced Cluster Management for Kubernetes 2.4.8 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs. See the following<br>Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.4/html/release_notes/" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.4/html/release_notes/</a> Security fixes:<br><li> moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129)</li> <li> nodejs: undici vulnerable to CRLF via content headers (CVE-2022-35948)</li> <li> nodejs: undici.request vulnerable to SSRF (CVE-2022-35949)</li> <li> terser: insecure use of regular expressions leads to ReDoS (CVE-2022-25858)</li> <li> search-api: SQL injection leads to remote denial of service (CVE-2022-2238)</li> Bug fix: <br><li> RHACM 2.4.8 images (BZ# 2130745)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Advanced Cluster Management |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:7276 is classified as important.
To fix RHSA-2022:7276, you should update Red Hat Advanced Cluster Management for Kubernetes to the latest patched version.
RHSA-2022:7276 affects Red Hat Advanced Cluster Management for Kubernetes version 2.4.8.
Not addressing RHSA-2022:7276 can lead to vulnerabilities that may be exploited to compromise the security of your Kubernetes environment.
Yes, there is an official advisory for RHSA-2022:7276 available from Red Hat.