Where
-Infinity
0
Severity
5.5
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy basic-auth credentials in the must-gather archive, potentially disclosing sensitive authentication information to anyone with access to the archive.

1 / 2
Source: MITRE
First published (updated )
Severity
4.4
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

A flaw was found in the submariner-operator component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path. This lack of validation enables an attacker to execute arbitrary code with elevated privileges across the entire cluster, including control-plane nodes, by deploying a malicious image.

1 / 2
Source: MITRE
First published (updated )

Red Hat Advanced Cluster Management for Kubernetes provides thecapabilities to address common challenges that administrators and sitereliability engineers face as they work across a range of public andprivate cloud environments. Clusters and applications are all visible andmanaged from a single console—with security policy built in.This advisory contains the container images for Red Hat Advanced ClusterManagement for Kubernetes, which add new features and enhancements, bugfixes, and updated container images. See the followingRelease Notes documentation, which will be updated shortly for thisrelease, for additional details about this release:https://docs.redhat.com/en/documentation/redhatadvancedclustermanagementforkubernetes/2.11/html-single/releasenotes/index#acm-release-notes

First published (updated )

Red Hat Advanced Cluster Management for Kubernetes provides thecapabilities to address common challenges that administrators and sitereliability engineers face as they work across a range of public andprivate cloud environments. Clusters and applications are all visible andmanaged from a single console—with security policy built in.This advisory contains the container images for Red Hat Advanced ClusterManagement for Kubernetes, which add new features and enhancements, bugfixes, and updated container images. See the followingRelease Notes documentation, which will be updated shortly for thisrelease, for additional details about this release:https://docs.redhat.com/en/documentation/redhatadvancedclustermanagementforkubernetes/2.13/html-single/releasenotes/index#acm-release-notes

First published (updated )

Red Hat Advanced Cluster Management for Kubernetes provides thecapabilities to address common challenges that administrators and sitereliability engineers face as they work across a range of public andprivate cloud environments. Clusters and applications are all visible andmanaged from a single console—with security policy built in.This advisory contains the container images for Red Hat Advanced ClusterManagement for Kubernetes, which add new features and enhancements, bugfixes, and updated container images. See the followingRelease Notes documentation, which will be updated shortly for thisrelease, for additional details about this release:https://docs.redhat.com/en/documentation/redhatadvancedclustermanagementforkubernetes/2.14/html-single/releasenotes/index#acm-release-notes

First published (updated )
Severity
7

Important: Red Hat Advanced Cluster Management for Kubernetes v2.14.3 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

Important: Red Hat Advanced Cluster Management for Kubernetes 2.14.1 security update

1 / 2
Source: Red Hat

Remedy

Before you apply this update, make sure all previously released errata<br>that are relevant to your system are applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat Advanced Cluster Management for Kubernetes 2.12.6 security update

1 / 2
Source: Red Hat

Remedy

Before you apply this update, make sure all previously released errata<br>that are relevant to your system are applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat Advanced Cluster Management for Kubernetes 2.12.6 security update

Remedy

Before you apply this update, make sure all previously released errata<br>that are relevant to your system are applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: RHSA: Submariner 0.20.1 - bug fix and enhancement update

Remedy

To learn more about Submariner, see <a href="https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/networking/networking#submariner." target="_blank">https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/networking/networking#submariner.</a>
First published (updated )
Severity
7

Important: Red Hat Advanced Cluster Management 2.13.3 fixes and container updates

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.
First published (updated )
Severity
7

Important: Red Hat Advanced Cluster Management 2.9.9 bug fixes and container updates

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.
First published (updated )
Severity
7

Important: RHSA: Submariner 0.18.5 - bug and security update

1 / 2
Source: Red Hat

Remedy

To learn more about Submariner, see <a href="https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/networking/networking#submariner." target="_blank">https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/networking/networking#submariner.</a>
First published (updated )
Severity
7

Important: Red Hat Advanced Cluster Management 2.11.7 container updates

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released erratas are<br>relevant and have been applied to your system.
First published (updated )
Severity
7

Important: Red Hat Advanced Cluster Management 2.10.8 container updates

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released erratas are<br>relevant and have been applied to your system.
First published (updated )
Severity
7

Important: RHSA: Submariner 0.19.4 - bug fix and enhancement update

1 / 2
Source: Red Hat

Remedy

To learn more about Submariner, see <a href="https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/networking/networking#submariner." target="_blank">https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/networking/networking#submariner.</a>
First published (updated )
Severity
7

Important: Red Hat Advanced Cluster Management 2.12.3 container image updates

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released erratas are<br>relevant and have been applied to your system.
First published (updated )
Severity
7

Important: VolSync 0.11.2 security fixes and enhancements for RHEL 9

1 / 2
Source: Red Hat

Remedy

For more details, see the Red Hat Advanced Cluster Management for Kubernetes<br>documentation:<br><a href="https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/business_continuity/business-cont-overview#volsync" target="_blank">https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/business_continuity/business-cont-overview#volsync</a>
First published (updated )
Severity
7.8
SSRF, CSRF
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check, allowing unauthenticated users making requests.

1 / 3
First published (updated )
Severity
7

Important: Red Hat Advanced Cluster Management 2.13.2 container image updates

Remedy

Before applying this update, make sure all previously released erratas are<br>relevant and have been applied to your system.
First published (updated )
Severity
7

Important: Red Hat Edge Manager Version 0.5.1 (Technology Preview) security fixes

1 / 2
Source: Red Hat

Remedy

See the following documentation for details on how to enable Red Hat Edge<br>Manager and more:<br><a href="https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.13/html-single/edge_manager/index#edge-mgr-intro" target="_blank">https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.13/html-single/edge_manager/index#edge-mgr-intro</a>
First published (updated )
Severity
7

Important: RHSA: Submariner 0.19.2 - bug fix and enhancement update

1 / 2
Source: Red Hat

Remedy

To learn more about Submariner, see <a href="https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/networking/networking#submariner" target="_blank">https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/networking/networking#submariner</a>
First published (updated )
Severity
7

Important: Red Hat Advanced Cluster Management 2.12.2 security and bug fix updates

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.
First published (updated )
Severity
7

Important: RHSA: Submariner 0.17.5 - bug and security fixes

Remedy

To learn more about Submariner, see <a href="https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.10/html/networking/networking#submariner" target="_blank">https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.10/html/networking/networking#submariner</a>
First published (updated )
Severity
7

Important: Red Hat Advanced Cluster Management 2.11.5 bug fixes and container updates

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.
First published (updated )
Severity
7

Important: RHSA: Submariner 0.16.8 - bug and security fixes

1 / 2
Source: Red Hat

Remedy

To learn more about Submariner, see <a href="https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/networking/networking#submariner" target="_blank">https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/networking/networking#submariner</a>
First published (updated )
Severity
7

Important: Red Hat Advanced Cluster Management 2.9.6 bug fixes and container updates

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.
First published (updated )
Severity
7

Important: RHSA: Submariner 0.18.4 - bug and security fixes

1 / 2
Source: Red Hat

Remedy

To learn more about Submariner, see <a href="https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/networking/networking#submariner" target="_blank">https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/networking/networking#submariner</a>
First published (updated )
Severity
7

Important: VolSync 0.10.2 for RHEL 9

1 / 2
Source: Red Hat

Remedy

For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:<br><a href="https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/business_continuity/business-cont-overview#volsync" target="_blank">https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/business_continuity/business-cont-overview#volsync</a>
First published (updated )
Severity
4
XSS

Moderate: Red Hat Advanced Cluster Management 2.11.4 security enhancements and bug fixes

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released erratas are<br>relevant and have been applied to your system.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203