RHSA-2024:0820: Critical: Red Hat Advanced Cluster Management 2.8.5 security and bug fix container updates
Critical: Red Hat Advanced Cluster Management 2.8.5 security and bug fix container updates
Other sources
Red Hat Advanced Cluster Management for Kubernetes 2.8.5 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs. See the following<br>Release Notes documentation:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.8/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.8/html/releasenotes/</a> Security fix(es):<br>CVE-2023-49568 go-git: Maliciously crafted Git server replies can cause DoS on<br>go-git clients<br>CVE-2023-49569 go-git: Maliciously crafted Git server replies can lead to path<br>traversal and RCE on go-git clients<br>Jira issues addressed:<br><li> ACM-7547: Search - AddOnDeploymentConfig toleration is not updated automatically</li> <li> ACM-8415: ACM Policy that applies stringdata in a secret regression with templates</li> <li> ACM-8696: Having baremetalhost.metal3.io in ACM backup results in some issues when restored</li> <li> ACM-8764: Addons not deployed on ACM managed cluster when the managed cluster is imported</li> <li> ACM-8857: credentials restore file is executed after resources restore</li> <li> ACM-8947: Configuration Policy controller unexpectedly gets taken out of uninstall mode</li> <li> ACM-8967: oc get policy still returns NonCompliant 10 minutes after deleting the certificate and secret</li> <li> ACM-9466: cluster detail page optimisations</li>
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:0820?
The severity of RHSA-2024:0820 is classified as Critical due to significant security vulnerabilities.
How do I fix RHSA-2024:0820?
To fix RHSA-2024:0820, you need to update your Red Hat Advanced Cluster Management for Kubernetes to version 2.8.5.
What are the main vulnerabilities addressed in RHSA-2024:0820?
RHSA-2024:0820 addresses multiple security vulnerabilities and bug fixes that impact Red Hat Advanced Cluster Management for Kubernetes.
Who is affected by RHSA-2024:0820?
RHSA-2024:0820 affects users of Red Hat Advanced Cluster Management for Kubernetes version prior to 2.8.5.
When was RHSA-2024:0820 released?
RHSA-2024:0820 was released in response to critical security findings and bug fixes for Red Hat Advanced Cluster Management for Kubernetes.