RHSA-2025:0723: Important: Multicluster Engine for Kubernetes 2.7.3 security updates and bug fixes
Important: Multicluster Engine for Kubernetes 2.7.3 security updates and bug fixes
Other sources
Multicluster engine for Kubernetes v2.7.3 images<br>Multicluster engine for Kubernetes provides the foundational components<br>that are necessary for the centralized management of multiple<br>Kubernetes-based clusters across data centers, public clouds, and private<br>clouds.<br>You can use the engine to create new Red Hat OpenShift Container Platform<br>clusters or to bring existing Kubernetes-based clusters under management by<br>importing them. After the clusters are managed, you can use the APIs that<br>are provided by the engine to distribute configuration based on placement<br>policy.<br>Security fix(es):<br><li> nanoid mishandles non-integer values (CVE-2024-55565)</li> <li> Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337)</li>
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:0723?
RHSA-2025:0723 is classified as important due to security updates and bug fixes in Multicluster Engine for Kubernetes.
How do I fix RHSA-2025:0723?
To fix RHSA-2025:0723, upgrade to the latest available version of Multicluster Engine for Kubernetes as recommended in the security advisory.
What components are affected by RHSA-2025:0723?
RHSA-2025:0723 affects the Multicluster Engine for Kubernetes version 2.7.3 and its associated images.
What vulnerabilities are addressed by RHSA-2025:0723?
RHSA-2025:0723 addresses multiple security vulnerabilities as part of the updates for the Multicluster Engine for Kubernetes.
Is there a known workaround for RHSA-2025:0723?
There are no specific workarounds for RHSA-2025:0723; upgrading to a patched version is the recommended approach.