A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI. This information should only be accessible to authorized users and may result in the loss of confidentiality of administrative information, which could be leaked to unauthorized actors.
Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs. See the following<br>Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://docs.redhat.com/en/documentation/redhatadvancedclustermanagementforkubernetes/2.10" target="blank">https://docs.redhat.com/en/documentation/redhatadvancedclustermanagementforkubernetes/2.10</a> Security Fix(es) from Bugzilla:<br><li> opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics (CVE-2023-47108)</li> <li> opentelemetry: DoS vulnerability in otelhttp (CVE-2023-45142)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, and other related information, refer to the CVE page(s) listed in the<br>References section.
Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>Security Fixes: <br><li> golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288) </li> This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs. See the following<br>Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.8/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.8/html/releasenotes/</a>
Security Fix(es) CVE-2023-29017 vm2: Sandbox Escape CVE-2023-29199 vm2: Sandbox Escape CVE-2023-30547 vm2: Sandbox Escape when exception sanitization
Red Hat Advanced Cluster Management for Kubernetes 2.6.4 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs. See the following<br>Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.6/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.6/html/releasenotes/</a> Issue addressed:<br><li> RHACM 2.6.4 images (BZ# 2153382)</li> Security fixes:<br><li> CVE-2022-24999 express: "qs" prototype poisoning causes the hang of the node process</li>
Red Hat Advanced Cluster Management for Kubernetes 2.6.3 imagesRed Hat Advanced Cluster Management for Kubernetes provides thecapabilities to address common challenges that administrators and sitereliability engineers face as they work across a range of public andprivate cloud environments. Clusters and applications are all visible andmanaged from a single console—with security policy built in.This advisory contains the container images for Red Hat Advanced ClusterManagement for Kubernetes, which fix several bugs. See the followingRelease Notes documentation, which will be updated shortly for thisrelease, for additional details about this release:https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.6/html/releasenotes/ Bugs addressed: clusters belong to global clusterset is not selected by placement when rescheduling (BZ# 2129679) RHACM 2.6.3 images (BZ# 2139085) Security fixes: CVE-2022-3517 nodejs-minimatch: ReDoS via the braceExpand function Security CVE-2022-41912 crewjam/saml: Authentication bypass when processing SAML responses containing multiple Assertion elements
Red Hat Advanced Cluster Management for Kubernetes 2.6.2 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs. See the following<br>Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.6/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.6/html/releasenotes/</a> Security fixes:<br><li> moment: inefficient parsing algorithm resulting in DoS (CVE-2022-31129)</li> <li> passport: incorrect session regeneration (CVE-2022-25896)</li> <li> sanitize-html: insecure global regular expression replacement logic may lead to ReDoS (CVE-2022-25887)</li> <li> terser: insecure use of regular expressions leads to ReDoS (CVE-2022-25858)</li> <li> search-api: SQL injection leads to remote denial of service (CVE-2022-2238)</li> Bug fixes:<br><li> ACM 2.6.2 images (BZ# 2126195)</li> <li> Infra MachineSet Replicate Taint (BZ# 2116528)</li> <li> Work agent panic when apply the manifestwork (BZ# 2120920)</li> <li> unexpected difference of behavior in inform policies with lists of apiGroups for ClusterRole resources (BZ# 2130985)</li>
Red Hat Advanced Cluster Management for Kubernetes 2.4.6 imagesRed Hat Advanced Cluster Management for Kubernetes provides thecapabilities to address common challenges that administrators and sitereliability engineers face as they work across a range of public andprivate cloud environments. Clusters and applications are all visible andmanaged from a single console—with security policy built in.This advisory contains the container images for Red Hat Advanced ClusterManagement for Kubernetes, which fix several security issues and several bugs. See the followingRelease Notes documentation, which will be updated shortly for thisrelease, for additional details about this release:https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.4/html/releasenotes/ Security fixes: golang: crypto/tls: session tickets lack random ticketageadd (CVE-2022-30629) moment: inefficient parsing algorithim resulting in DoS (CVE-2022-31129) nodejs16: CRLF injection in node-undici (CVE-2022-31150) nodejs/undici: Cookie headers uncleared on cross-origin redirect (CVE-2022-31151) vm2: Sandbox Escape in vm2 (CVE-2022-36067) Bug fixes: RHACM 2.4 using deprecated APIs in managed clusters (BZ# 2041540) vSphere network name doesn't allow entering spaces and doesn't reflect YAML changes (BZ# 2074766) cluster update status is stuck, also update is not even visible (BZ# 2079418) Policy that creates cluster role is showing as not compliant due to Request entity too large message (BZ# 2088486) Upgraded from RHACM 2.2-->2.3-->2.4 and cannot create cluster (BZ# 2089490) ACM Console Becomes Unusable After a Time (BZ# 2097464) RHACM 2.4.6 images (BZ# 2100613) Cluster Pools with conflicting name of existing clusters in same namespace fails creation and deletes existing cluster (BZ# 2102436) ManagedClusters in Pending import state after ACM hub migration (BZ# 2102495)
Red Hat Advanced Cluster Management for Kubernetes 2.6.0 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix security issues and several bugs. See the following Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.6/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.6/html/releasenotes/</a> Security fixes: <br><li> CVE-2022-31129 moment: inefficient parsing algorithm resulting in DoS</li> <li> CVE-2022-30629 golang: crypto/tls: session tickets lack random ticketageadd</li> <li> CVE-2022-1705 golang: net/<a href="http:" target="blank">http:</a> improper sanitization of Transfer-Encoding header</li> <li> CVE-2022-1962 golang: go/parser: stack exhaustion in all Parse functions</li> <li> CVE-2022-28131 golang: encoding/xml: stack exhaustion in Decoder.Skip</li> <li> CVE-2022-30630 golang: io/fs: stack exhaustion in Glob</li> <li> CVE-2022-30631 golang: compress/gzip: stack exhaustion in Reader.Read</li> <li> CVE-2022-30632 golang: path/filepath: stack exhaustion in Glob</li> <li> CVE-2022-30633 golang: encoding/xml: stack exhaustion in Unmarshal</li> <li> CVE-2022-30635 golang: encoding/gob: stack exhaustion in Decoder.Decode</li> <li> CVE-2022-32148 golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working</li> Bug fixes:<br><li> assisted-service repo pin-latest.py script should allow custom tags to be pinned (BZ# 2065661)</li> <li> assisted-service-build image is too big in size (BZ# 2066059)</li> <li> assisted-service pin-latest.py script should exclude the postgres image (BZ# 2076901)</li> <li> PXE artifacts need to be served via HTTP (BZ# 2078531)</li> <li> Implementing new service-agent protocol on agent side (BZ# 2081281)</li> <li> RHACM 2.6.0 images (BZ# 2090906)</li> <li> Assisted service POD keeps crashing after a bare metal host is created (BZ# 2093503)</li> <li> Assisted service triggers the worker nodes re-provisioning on the hub cluster when the converged flow is enabled (BZ# 2096106)</li> <li> Fix assisted CI jobs that fail for cluster-info readiness (BZ# 2097696)</li> <li> Nodes are required to have installation disks of at least 120GB instead of at minimum of 100GB (BZ# 2099277)</li> <li> The pre-selected search keyword is not readable (BZ# 2107736)</li> <li> The value of label expressions in the new placement for policy and policysets cannot be shown real-time from UI (BZ# 2111843)</li>
Red Hat Advanced Cluster Management for Kubernetes 2.3.12 imagesRed Hat Advanced Cluster Management for Kubernetes provides thecapabilities to address common challenges that administrators and sitereliability engineers face as they work across a range of public andprivate cloud environments. Clusters and applications are all visible andmanaged from a single console—with security policy built in.This advisory contains the container images for Red Hat Advanced ClusterManagement for Kubernetes, which fix several bugs. See the followingRelease Notes documentation, which will be updated shortly for thisrelease, for additional details about this release:https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.3/html/releasenotes/ Security fix: CVE-2022-31129 moment: inefficient parsing algorithm resulting in DoS Bug fixes: Remove 1.9.1 from Proxy Patch Documentation (BZ# 2076856) RHACM 2.3.12 images (BZ# 2101411)
Red Hat Advanced Cluster Management for Kubernetes 2.5.1 imagesRed Hat Advanced Cluster Management for Kubernetes provides thecapabilities to address common challenges that administrators and sitereliability engineers face as they work across a range of public andprivate cloud environments. Clusters and applications are all visible andmanaged from a single console—with security policy built in.This advisory contains the container images for Red Hat Advanced ClusterManagement for Kubernetes, which fix several bugs. See the followingRelease Notes documentation, which will be updated shortly for thisrelease, for additional details about this release:https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.5/html/releasenotes/ Security update: nats-server: misusing the "dynamically provisioned sandbox accounts" feature authenticated user can obtain the privileges of the System account (CVE-2022-24450) Bug fixes: Can't install submariner add-ons from UI on unsupported cloud provider (BZ# 2087686) policy controller addons are Progressing status (unhealthy from backend) on OCP3.11 in ARM hub (BZ# 2088270) RHACM 2.5.1 images (BZ# 2090802) Broken link to Submariner manual install instructions (BZ# 2095333) The backend service is unavailable when accessing ACM 2.5 Overview page (BZ# 2096389) 64 character length causing clusters to unsubscribe (BZ# 2101453)
Red Hat Advanced Cluster Management for Kubernetes 2.4.3 imagesRed Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in.This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which provide some security fixes and bug fixes. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release:https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.4/html/releasenotes/ Security updates: golang.org/x/crypto: empty plaintext packet causes panic (CVE-2021-43565) nats-server: misusing the "dynamically provisioned sandbox accounts" feature authenticated user can obtain the privileges of the System account (CVE-2022-24450) nanoid: Information disclosure via valueOf() function (CVE-2021-23566) nodejs-shelljs: improper privilege management (CVE-2022-0144) search-ui-container: follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor (CVE-2022-0155) node-fetch: exposure of sensitive information to an unauthorized actor (CVE-2022-0235) follow-redirects: Exposure of Sensitive Information via Authorization Header leak (CVE-2022-0536) openssl: Infinite loop in BNmodsqrt() reachable when parsing certificates (CVE-2022-0778) imgcrypt: Unauthorized access to encryted container image on a shared system due to missing check in CheckAuthorization() code path (CVE-2022-24778) golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191) opencontainers: OCI manifest and index parsing confusion (CVE-2021-41190) Related bugs: RHACM 2.4.3 image files (BZ #2057249) Observability - dashboard name contains / would cause error when generating dashboard cm (BZ #2032128) ACM application placement fails after renaming the application name (BZ #2033051) Disable the obs metric collect should not impact the managed cluster upgrade (BZ #2039197) Observability - cluster list should only contain OCP311 cluster on OCP311 dashboard (BZ #2039820) The value of name label changed from clusterclaim name to cluster name (BZ #2042223) VMWare Cluster creation does not accept ecdsa-sha2-nistp521 ssh keys (BZ #2048500) clusterSelector matchLabels spec are cleared when changing app name/namespace during creating an app in UI (BZ #2053211) Application cluster status is not updated in UI after restoring (BZ #2053279) OpenStack cluster creation is using deprecated floating IP config for 4.7+ (BZ #2056610) The value of Vendor reported by cluster metrics was Other even if the vendor label in managedcluster was Openshift (BZ #2059039) Subscriptions stop reconciling after channel secrets are recreated (BZ #2059954) Placementrule is not reconciling on a new fresh environment (BZ #2074156) The cluster claimed from clusterpool cannot auto imported (BZ #2074543)
Red Hat Advanced Cluster Management for Kubernetes 2.3.8 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs. See the following<br>Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.3/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.3/html/releasenotes/</a> Security updates:<br><li> nanoid: Information disclosure via valueOf() function (CVE-2021-23566)</li> <li> nodejs-shelljs: improper privilege management (CVE-2022-0144)</li> <li> follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor (CVE-2022-0155)</li> <li> node-fetch: exposure of sensitive information to an unauthorized actor (CVE-2022-0235)</li> <li> follow-redirects: Exposure of Sensitive Information via Authorization Header leak (CVE-2022-0536)</li> Bug fix:<br><li> RHACM 2.3.8 images (Bugzilla #2062316)</li>
Red Hat Advanced Cluster Management for Kubernetes 2.2.11 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments.<br>Clusters and applications are all visible and managed from a single console — with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which provide security fixes, bug fixes and container upgrades. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.2/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.2/html/releasenotes/</a> Security updates:<br><li> object-path: Type confusion vulnerability can lead to a bypass of CVE-2020-15256 (CVE-2021-23434)</li> <li> follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor (CVE-2022-0155)</li> Related bugs: <br><li> RHACM 2.2.11 images (Bugzilla #2029508)</li> <li> ClusterImageSet has 4.5 which is not supported in ACM 2.2.10 (Bugzilla #2030859)</li>
Red Hat Advanced Cluster Management for Kubernetes 2.3.6 imagesRed Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE links in the References section.This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which provide some security fixes and bug fixes. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release:https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.3/html/releasenotes/ Security updates: Nodejs-json-schema: Prototype pollution vulnerability (CVE-2021-3918) Nanoid: Information disclosure via valueOf() function (CVE-2021-23566) Golang.org/x/crypto: empty plaintext packet causes panic (CVE-2021-43565) Follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor (CVE-2022-0155) Bug fixes: Inform ACM policy is not checking properly the node fields (BZ# 2015588) ImagePullPolicy is "Always" for multicluster-operators-subscription-rhel8 image (BZ# 2021128) Traceback blocks reconciliation of helm repository hosted on AWS S3 storage (BZ# 2021576) RHACM 2.3.6 images (BZ# 2029507) Console UI enabled SNO UI Options not displayed during cluster creating (BZ# 2030002) Grc pod restarts for each new GET request to the Governance Policy Page (BZ# 2037351) Clustersets do not appear in UI (BZ# 2049810)
Red Hat Advanced Cluster Management for Kubernetes 2.4.2 imagesRed Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE links in the References section.This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which provide some security fixes and bug fixes. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release:https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.4/html/releasenotes/ Security updates: nodejs-json-schema: Prototype pollution vulnerability (CVE-2021-3918) containerd: Unprivileged pod may bind mount any privileged regular file on disk (CVE-2021-43816) minio-go: user privilege escalation in AddUser() admin API (CVE-2021-43858) nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes (CVE-2021-3807) fastify-static: open redirect via an URL with double slash followed by a domain (CVE-2021-22963) moby: docker cp allows unexpected chmod of host file (CVE-2021-41089) moby: data directory contains subdirectories with insufficiently restricted permissions, which could lead to directory traversal (CVE-2021-41091) golang.org/x/crypto: empty plaintext packet causes panic (CVE-2021-43565) node-fetch: Exposure of Sensitive Information to an Unauthorized Actor (CVE-2022-0235) nats-server: misusing the "dynamically provisioned sandbox accounts" feature authenticated user can obtain the privileges of the System account (CVE-2022-24450) Bug fixes: Trying to create a new cluster on vSphere and no feedback, stuck in "creating" (Bugzilla #1937078) The hyperlink of ks cluster node cannot be opened when I want to check the node (Bugzilla #2028100) Unable to make SSH connection to a Bitbucket server (Bugzilla #2028196) RHACM cannot deploy Helm Charts with version numbers starting with letters (e.g. v1.6.1) (Bugzilla #2028931) RHACM 2.4.2 images (Bugzilla #2029506) Git Application still appears in Application Table and Resources are Still Seen in Advanced Configuration Upon Deletion after Upgrade from 2.4.0 (Bugzilla #2030005) Namespace left orphaned after destroying the cluster (Bugzilla #2030379) The results filtered through the filter contain some data that should not be present in cluster page (Bugzilla #2034198) Git over ssh doesn't use custom port set in url (Bugzilla #2036057) The value of name label changed from clusterclaim name to cluster name (Bugzilla #2042223) ACM configuration policies do not handle Limitrange or Quotas values (Bugzilla #2042545) Cluster addons do not appear after upgrade from ACM 2.3.5 to ACM 2.3.6 (Bugzilla #2050847) The azure government regions were not list in the region drop down list when creating the cluster (Bugzilla #2051797)
Red Hat Advanced Cluster Management for Kubernetes 2.2.10 imagesRed Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments.Clusters and applications are all visible and managed from a single console — with security policy built in.This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which provide security fixes, bug fixes and container upgrades. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release:https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.2/html/releasenotes/ Security fixes: CVE-2021-3795 semver-regex: inefficient regular expression complexity CVE-2021-23440 nodejs-set-value: type confusion allows bypass of CVE-2019-10747 Related bugs: RHACM 2.2.10 images (Bugzilla #2013652)
Red Hat Advanced Cluster Management for Kubernetes 2.3.3 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with<br>security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which fix several bugs and provide security updates. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.3/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.3/html/releasenotes/</a> Note: Because Red Hat OpenShift Container Platform version 4.9 was just released, the functional testing of the compatibility between Red Hat Advanced Cluster Management 2.3.3 and Red Hat OpenShift Container Platform version 4.9 is still in progress.<br>Security fixes: <br><li> nginx: Off-by-one in ngxresolvercopy() when labels are followed by a pointer to a root domain name (CVE-2021-23017)</li> <li> redis: Lua scripts can overflow the heap-based Lua stack (CVE-2021-32626)</li> <li> redis: Integer overflow issue with Streams (CVE-2021-32627)</li> <li> redis: Integer overflow bug in the ziplist data structure (CVE-2021-32628)</li> <li> redis: Integer overflow issue with intsets (CVE-2021-32687)</li> <li> redis: Integer overflow issue with strings (CVE-2021-41099)</li> <li> redis: Out of bounds read in lua debugger protocol parser (CVE-2021-32672)</li> <li> redis: Denial of service via Redis Standard Protocol (RESP) request (CVE-2021-32675)</li> <li> helm: information disclosure vulnerability (CVE-2021-32690)</li> Bug fixes:<br><li> KUBE-API: Support move agent to different cluster in the same namespace (BZ# 1977358)</li> <li> Add columns to the Agent CRD list (BZ# 1977398)</li> <li> ClusterDeployment controller watches all Secrets from all namespaces (BZ# 1986081)</li> <li> RHACM 2.3.3 images (BZ# 1999365)</li> <li> Workaround for Network Manager not supporting nmconnections priority (BZ# 2001294)</li> <li> create cluster page empty in Safary Browser (BZ# 2002280)</li> <li> Compliance state doesn't get updated after fixing the issue causing initially the policy not being able to update the managed object (BZ# 2002667)</li> <li> Overview page displays VMware based managed cluster as other (BZ# 2004188)</li>
Red Hat Advanced Cluster Management for Kubernetes 2.2.9 imagesRed Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments.Clusters and applications are all visible and managed from a single console — with security policy built in.This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which provide bug fixes and security fixes. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release:https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.2/html/releasenotes/ Security fixes: nginx: Off-by-one in ngxresolvercopy() when labels are followed by a pointer to a root domain name (CVE-2021-23017) redis: Lua scripts can overflow the heap-based Lua stack (CVE-2021-32626) redis: Integer overflow issue with Streams (CVE-2021-32627) redis: Integer overflow bug in the ziplist data structure (CVE-2021-32628) redis: Integer overflow issue with intsets (CVE-2021-32687) redis: Integer overflow issue with strings (CVE-2021-41099) redis: Out of bounds read in lua debugger protocol parser (CVE-2021-32672) redis: Denial of service via Redis Standard Protocol (RESP) request (CVE-2021-32675) object-path: Type confusion vulnerability can lead to a bypass of CVE-2020-15256 (CVE-2021-23434) Bug fixes: RHACM 2.2.9 images (BZ #1999601)
Red Hat Advanced Cluster Management for Kubernetes 2.1.11 imagesRed Hat Advanced Cluster Management for Kubernetes provides thecapabilities to address common challenges that administrators and sitereliability engineers face as they work across a range of public andprivate cloud environments. Clusters and applications are all visible andmanaged from a single console—with security policy built in.This advisory contains updates to one or more container images for Red HatAdvanced Cluster Management for Kubernetes. See the following Release Notesdocumentation, which will be updated shortly for this release, for additionaldetails about this release:https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.1/html/releasenotes/ Security fix: management-ingress-container: nginx: Off-by-one in ngxresolvercopy() when labels are followed by a pointer to a root domain name (CVE-2021-23017) For more details about the security issue, including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.Container updates: RHACM 2.1.11 images (BZ# 1999375)
Red Hat Advanced Cluster Management for Kubernetes 2.2.4 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site reliability<br>engineers face as they work across a range of public and private cloud environments.<br>Clusters and applications are all visible and managed from a single<br>console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs and security issues. See<br>the following Release Notes documentation, which will be updated shortly for<br>this release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.2/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.2/html/releasenotes/</a> Security fixes:<br><li> redisgraph-tls: redis: integer overflow when configurable limit for maximum supported bulk input size is too big on 32-bit platforms (CVE-2021-21309)</li> <li> console-header-container: nodejs-netmask: improper input validation of octal input data (CVE-2021-28092)</li> <li> console-container: nodejs-is-svg: ReDoS via malicious string (CVE-2021-28918)</li> Bug fixes: <br><li> RHACM 2.2.4 images (BZ# 1957254)</li> <li> Enabling observability for OpenShift Container Storage with RHACM 2.2 on OCP 4.7 (BZ#1950832)</li> <li> ACM Operator should support using the default route TLS (BZ# 1955270)</li> <li> The scrolling bar for search filter does not work properly (BZ# 1956852)</li> <li> Limits on Length of MultiClusterObservability Resource Name (BZ# 1959426)</li> <li> The proxy setup in install-config.yaml is not worked when IPI installing with RHACM (BZ# 1960181)</li> <li> Unable to make SSH connection to a Bitbucket server (BZ# 1966513)</li> <li> Observability Thanos store shard crashing - cannot unmarshall DNS message (BZ# 1967890)</li>
Red Hat Advanced Cluster Management for Kubernetes 2.2.3 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to<br>address common challenges that administrators and site reliability engineers<br>face as they work across a range of public and private cloud environments.<br>Clusters and applications are all visible and managed from a single console—with<br>security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs and security issues. See the<br>following Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.2/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.2/html/releasenotes/</a> Security fixes:<br><li> nodejs-underscore: Arbitrary code execution via the template function (CVE-2021-23358)</li> <li> nodejs-netmask: improper input validation of octal input data (CVE-2021-28918)</li> <li> nodejs-glob-parent: Regular expression denial of service (CVE-2020-28469)</li> <li> nodejs-is-svg: ReDoS via malicious string (CVE-2021-28092)</li> <li> nodejs-netmask: incorrectly parses an IP address that has octal integer with invalid character (CVE-2021-29418)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>pages listed in the References section.<br>Bug fixes: <br><li> ACM UI is not escaping cluster names (BZ# 1936883)</li> <li> specify "folder:" for vsphere cluster creation result empty namespace ,no hive (BZ# 1943092)</li> <li> RHACM 2.2.3 images (BZ# 1949103)</li> <li> Applications won't create properly on native K8S cluster (BZ# 1951384)</li>
Red Hat Advanced Cluster Management for Kubernetes 2.0.10 imagesRed Hat Advanced Cluster Management for Kubernetes provides thecapabilities to address common challenges that administrators and sitereliability engineers face as they work across a range of public andprivate cloud environments. Clusters and applications are all visible andmanaged from a single console—with security policy built in.This advisory contains the container images for Red Hat Advanced ClusterManagement for Kubernetes, which resolve some security issues and bugs. Seethe following Release Notes documentation, which will be updated shortlyfor this release, for details about thisrelease:https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.0/html/releasenotes/ Security fixes: nodejs-underscore: Arbitrary code execution via the template function (CVE-2021-23358) For more details about the security issue, including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.Bug fix: RHACM 2.0.10 images (BZ #1940452)
Red Hat Advanced Cluster Management for Kubernetes 2.2.2 imagesRed Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in.This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which fix several bugs and security issues. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release:https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.2/html/releasenotes/ Security Fix(es): fastify-reply-from: crafted URL allows prefix scape of the proxied backend service (CVE-2021-21321) fastify-http-proxy: crafted URL allows prefix scape of the proxied backend service (CVE-2021-21322) golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040) nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions (CVE-2020-28500) golang.org/x/text: Panic in language.ParseAcceptLanguage while parsing -u- extension (CVE-2020-28851) golang.org/x/text: Panic in language.ParseAcceptLanguage while processing bcp47 tag (CVE-2020-28852) go-slug: partial protection against zip slip attacks (CVE-2020-29529) nodejs-lodash: command injection via template (CVE-2021-23337) openssl: integer overflow in CipherUpdate (CVE-2021-23840) openssl: NULL pointer dereference in X509issuerandserialhash() (CVE-2021-23841) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): Documentation is referencing deprecated API for Service Export - Submariner (BZ#1936528) Importing of cluster fails due to error/typo in generated command (BZ#1936642) RHACM 2.2.2 images (BZ#1938215) 2.2 clusterlifecycle fails to allow provision fips: true clusters on aws, vsphere (BZ#1941778)
Red Hat Advanced Cluster Management for Kubernetes 2.1.3 imagesRed Hat Advanced Cluster Management for Kubernetes provides thecapabilities to address common challenges that administrators and sitereliability engineers face as they work across a range of public andprivate cloud environments. Clusters and applications are all visible andmanaged from a single console—with security policy built in.This advisory contains the container images for Red Hat Advanced ClusterManagement for Kubernetes, which fix several bugs and security issues. See the following Release Notes documentation,which will be updated shortly for this release, for additional details about thisrelease:https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.1/html/releasenotes/ Security fix: gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation. (CVE-2021-3121) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage(s) listed in the References section.Bug fixes: Moving from Patched ACM 2.1.x CSV to Default Results in Degraded Cluster (BZ #1906142) Managed Cluster in RHACM stays in Pending Import state (BZ#1894778) RHACM 2.1.0 Custom CA/Cert not working with observability component (BZ#1906542) Policy Standards, Categories and Controls value listing is not consistent across pages (BZ#1896399) Page gets blanks when YAML editor is cleared in policy creation page (BZ#1901447) Content for a page with invalid namespace in URL keeps on loading (BZ#1903580) Missing git repo secret causes multicluster-operators-hub-subscription to crash (BZ#1918799)