First published: Mon Oct 30 2023(Updated: )
Red Hat Advanced Cluster Management for Kubernetes 2.6.8 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs. See the following<br>Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.6/html/release_notes/" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.6/html/release_notes/</a> Security fix(es):<br>CVE-2023-44487 HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack<br>CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work<br>CVE-2023-39321 golang: crypto/tls: panic when processing post-handshake message on QUIC connections<br>CVE-2023-39319 golang: html/template: improper handling of special tags within script contexts<br>CVE-2023-39318 golang: html/template: improper handling of HTML-like comments within script contexts<br>CVE-2023-39322 golang: crypto/tls: lack of a limit on buffered post-handshake
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Advanced Cluster Management |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:6202 is categorized as a moderate vulnerability.
To fix RHSA-2023:6202, users should update their Red Hat Advanced Cluster Management for Kubernetes to the latest patched version.
RHSA-2023:6202 addresses multiple vulnerabilities that could impact the security and stability of the Red Hat Advanced Cluster Management for Kubernetes.
RHSA-2023:6202 specifically applies to version 2.6.8 of Red Hat Advanced Cluster Management for Kubernetes.
RHSA-2023:6202 was released on December 6, 2023.