RHSA-2024:6236: Moderate: Red Hat Advanced Cluster Management 2.10.5 security and bug fix update
Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs. See the following<br>Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://docs.redhat.com/en/documentation/redhatadvancedclustermanagementforkubernetes/2.10" target="blank">https://docs.redhat.com/en/documentation/redhatadvancedclustermanagementforkubernetes/2.10</a> Security Fix(es) from Bugzilla:<br><li> opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics (CVE-2023-47108)</li> <li> opentelemetry: DoS vulnerability in otelhttp (CVE-2023-45142)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, and other related information, refer to the CVE page(s) listed in the<br>References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:6236?
The severity of RHSA-2024:6236 is classified as important.
How do I fix RHSA-2024:6236?
To fix RHSA-2024:6236, update Red Hat Advanced Cluster Management for Kubernetes to the latest patched version.
What vulnerabilities are addressed in RHSA-2024:6236?
RHSA-2024:6236 addresses multiple vulnerabilities that could affect the security of the Red Hat Advanced Cluster Management for Kubernetes.
Who is affected by RHSA-2024:6236?
Any organization using Red Hat Advanced Cluster Management for Kubernetes may be affected by RHSA-2024:6236.
What are the potential impacts of not addressing RHSA-2024:6236?
Failure to address RHSA-2024:6236 may lead to increased security risks and potential exploits on the affected software.