First published: Wed Oct 04 2023(Updated: )
Red Hat Advanced Cluster Management for Kubernetes 2.8.2 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs. See the following<br>Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.8/html/release_notes/" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.8/html/release_notes/</a> Jira issues resolved: <br><li> ACM-5398: ACM ignores Policies about empty label/field</li> <li> ACM-6003: UI throws "ClusterSets failed to load" error while deploying application set based applications from console</li> <li> ACM-6171: Policy shows as "Compliant" despite there being violations</li> Security fix(es):<br><li> CVE-2023-26136 tough-cookie: prototype pollution in cookie memstore</li> <li> CVE-2022-41721 x/net/http2/h2c: request smuggling</li> <li> CVE-2023-24539 html/template: improper sanitization of CSS values</li> <li> CVE-2023-24540 html/template: improper handling of JavaScript whitespace</li> <li> CVE-2023-29400 html/template: improper handling of empty HTML attributes</li>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Red Hat Advanced Cluster Management for Kubernetes |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:5442 is medium.
RHSA-2023:5442 affects Red Hat Advanced Cluster Management for Kubernetes.
Yes, you can find references for RHSA-2023:5442 here: [link1](https://access.redhat.com/errata/RHSA-2023:5442), [link2](https://bugzilla.redhat.com/show_bug.cgi?id=2162182), [link3](https://bugzilla.redhat.com/show_bug.cgi?id=2196026).