Where
-Infinity
0
Severity
8.2
AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.

1 / 2
Source: NVD
First published (updated )
Severity
7

Important: Multicluster Engine for Kubernetes 2.4.9 security updates and bug fixes

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview#mce-install-intro" target="_blank">https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview#mce-install-intro</a>
First published (updated )
Severity
7

Important: multicluster Engine for Kubernetes 2.6.7 container updates

1 / 2
Source: Red Hat

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#mce-install-intro" target="_blank">https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#mce-install-intro</a>
First published (updated )
Severity
7

Important: Multicluster Engine for Kubernetes 2.7.4 security updates

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/clusters/cluster_mce_overview#mce-install-intro" target="_blank">https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/clusters/cluster_mce_overview#mce-install-intro</a>
First published (updated )
Severity
7

Important: multicluster engine for Kubernetes 2.8.1 container image updates

1 / 2
Source: Red Hat

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/clusters/cluster_mce_overview#mce-install-intro" target="_blank">https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/clusters/cluster_mce_overview#mce-install-intro</a>
First published (updated )
Severity
7

Important: Multicluster Engine for Kubernetes 2.6.5 security updates and bug fixes

1 / 2
Source: Red Hat

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#mce-install-intro" target="_blank">https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#mce-install-intro</a>
First published (updated )
Severity
7

Important: Multicluster Engine for Kubernetes 2.7.3 security updates and bug fixes

1 / 2
Source: Red Hat

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/clusters/cluster_mce_overview#mce-install-intro" target="_blank">https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/clusters/cluster_mce_overview#mce-install-intro</a>
First published (updated )
Severity
7

Important: Multicluster Engine for Kubernetes 2.5.8 security updates and bug fixes

1 / 2
Source: Red Hat

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.10/html/clusters/cluster_mce_overview#mce-install-intro" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.10/html/clusters/cluster_mce_overview#mce-install-intro</a>
First published (updated )
Severity
7

Important: Multicluster Engine for Kubernetes 2.4.7 security updates and bug fixes

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview" target="_blank">https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview</a>
First published (updated )
Severity
4

Moderate: Multicluster Engine for Kubernetes 2.6.4 security enhancements and bug fixes

1 / 2
Source: Red Hat

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/clusters/cluster_mce_overview#mce-install-intro" target="_blank">https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/clusters/cluster_mce_overview#mce-install-intro</a>
First published (updated )
Severity
4

Moderate: Multicluster Engine for Kubernetes 2.7.2 security updates and bug fixes

1 / 2
Source: Red Hat

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/clusters/cluster_mce_overview#mce-install-intro" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/clusters/cluster_mce_overview#mce-install-intro</a>
First published (updated )
Severity
7

Important: Multicluster Engine for Kubernetes 2.3.8 bug fixes and container updates

1 / 2
Source: Red Hat

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.8/html/clusters/cluster_mce_overview#installing-while-connected-online-mce" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.8/html/clusters/cluster_mce_overview#installing-while-connected-online-mce</a>
First published (updated )
Severity
7

Important: Multicluster Engine for Kubernetes 2.4.6 security updates and bug fixes

1 / 2
Source: Red Hat

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/install_upgrade/installing-while-connected-online-mce" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/install_upgrade/installing-while-connected-online-mce</a>
First published (updated )
Severity
4

Moderate: Multicluster Engine for Kubernetes 2.6.3 security updates

1 / 2
Source: Red Hat

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#mce-install-intro" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.11/html/clusters/cluster_mce_overview#mce-install-intro</a>
First published (updated )
Severity
4

Moderate: Multicluster Engine for Kubernetes 2.5.7 security updates and bug fixes

1 / 2
Source: Red Hat

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.10/html/clusters/cluster_mce_overview#mce-install-intro" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.10/html/clusters/cluster_mce_overview#mce-install-intro</a>
First published (updated )

multicluster engine for Kubernetes v2.4.5 imagesmulticluster engine for Kubernetes provides the foundational componentsthat are necessary for the centralized management of multipleKubernetes-based clusters across data centers, public clouds, and privateclouds.You can use the engine to create new Red Hat OpenShift Container Platformclusters or to bring existing Kubernetes-based clusters under management byimporting them. After the clusters are managed, you can use the APIs thatare provided by the engine to distribute configuration based on placementpolicy.Jira issues addressed: ACM-10999 Import controller keeps refreshing the bootstrap hub kubeconfig ACM-9982 open-cluster-management-image-pull-credentials missing in open-cluster-management-agent-addon namespace in MCE 2.5.0-57

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview#installing-while-connected-online-mce" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview#installing-while-connected-online-mce</a>
First published (updated )

Multicluster engine for Kubernetes v2.5.3 imagesMulticluster engine for Kubernetes provides the foundational componentsthat are necessary for the centralized management of multipleKubernetes-based clusters across data centers, public clouds, and privateclouds.You can use the engine to create new Red Hat OpenShift Container Platformclusters or to bring existing Kubernetes-based clusters under management byimporting them. After the clusters are managed, you can use the APIs thatare provided by the engine to distribute configuration based on placementpolicy.Jira issues addressed: ACM-10580: HCP OpenShift Virtualization web console does not create clusters in HighAvailability mode

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.10/html/clusters/cluster_mce_overview#mce-install-intro" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.10/html/clusters/cluster_mce_overview#mce-install-intro</a>
First published (updated )

Multicluster engine for Kubernetes v2.5.2 imagesMulticluster engine for Kubernetes provides the foundational componentsthat are necessary for the centralized management of multipleKubernetes-based clusters across data centers, public clouds, and privateclouds.You can use the engine to create new Red Hat OpenShift Container Platformclusters or to bring existing Kubernetes-based clusters under management byimporting them. After the clusters are managed, you can use the APIs thatare provided by the engine to distribute configuration based on placementpolicy.

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.10/html/clusters/cluster_mce_overview#mce-install-intro" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.10/html/clusters/cluster_mce_overview#mce-install-intro</a>
First published (updated )
Severity
7

Important: Multicluster Engine for Kubernetes 2.2.9 security updates and bug fixes

1 / 2

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.7/html/clusters/cluster_mce_overview#installing-while-connected-online-mce" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.7/html/clusters/cluster_mce_overview#installing-while-connected-online-mce</a>
First published (updated )
Severity
4

Moderate: Multicluster Engine for Kubernetes 2.3.2 security updates and bug fixes

1 / 2

Remedy

For multicluster engine for Kubernetes, see the following documentation for details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.8/html/clusters/cluster_mce_overview#installing-while-connected-online-mce" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.8/html/clusters/cluster_mce_overview#installing-while-connected-online-mce</a>
First published (updated )
Severity
9

Critical: Multicluster Engine for Kubernetes 2.1.8 security updates and bug fixes

1 / 2

Remedy

For information and instructions for these updates, see the following article: <a href="https://access.redhat.com/solutions/7022540." target="_blank">https://access.redhat.com/solutions/7022540.</a> For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.6/html/multicluster_engine/multicluster_engine_overview#installing-while-connected-online-mce" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.6/html/multicluster_engine/multicluster_engine_overview#installing-while-connected-online-mce</a>
First published (updated )
Severity
9

Critical: Multicluster Engine for Kubernetes 2.3.1 security updates and bug fixes

1 / 2

Remedy

For information and instructions for these updates, see the following article: <a href="https://access.redhat.com/solutions/7022540." target="_blank">https://access.redhat.com/solutions/7022540.</a> For multicluster engine for Kubernetes, see the following documentation for details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.8/html/clusters/cluster_mce_overview#installing-while-connected-online-mce" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.8/html/clusters/cluster_mce_overview#installing-while-connected-online-mce</a>
First published (updated )
Severity
9

Critical: Multicluster Engine for Kubernetes 2.2.7 security updates and bug fixes

1 / 2

Remedy

For information and instructions for these updates, see the following article: <a href="https://access.redhat.com/solutions/7022540." target="_blank">https://access.redhat.com/solutions/7022540.</a> For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.7/html/clusters/cluster_mce_overview#installing-while-connected-online-mce" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.7/html/clusters/cluster_mce_overview#installing-while-connected-online-mce</a>
First published (updated )
Severity
9

Critical: Multicluster Engine for Kubernetes 2.0.9 security fixes and container updates

1 / 2

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.5/html-single/multicluster_engine_operator/index#installing-while-connected-online" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.5/html-single/multicluster_engine_operator/index#installing-while-connected-online</a>
First published (updated )
Severity
9

Critical: Multicluster Engine for Kubernetes 2.1.7 security fixes and container updates

Remedy

For multicluster engine for Kubernetes, see the following documentation for details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.6/html-single/multicluster_engine_operator/index#installing-while-connected-online" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.6/html-single/multicluster_engine_operator/index#installing-while-connected-online</a>
First published (updated )
Severity
9

Critical: Multicluster Engine for Kubernetes 2.2.4 security fixes and container updates

1 / 2

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.7/html/clusters/install_upgrade/installing-while-connected-online-mce" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.7/html/clusters/install_upgrade/installing-while-connected-online-mce</a>
First published (updated )

Multicluster Engine for Kubernetes 2.0.8 imagesMulticluster engine for Kubernetes provides the foundational componentsthat are necessary for the centralized management of multipleKubernetes-based clusters across data centers, public clouds, and privateclouds.You can use the engine to create new Red Hat OpenShift Container Platformclusters or to bring existing Kubernetes-based clusters under management byimporting them. After the clusters are managed, you can use the APIs thatare provided by the engine to distribute configuration based on placementpolicy.Security fix(es): CVE-2022-25881 http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability

Remedy

For multicluster engine for Kubernetes, see the following documentation for<br>details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.5/html/multicluster_engine/installing-while-connected-online" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.5/html/multicluster_engine/installing-while-connected-online</a>
First published (updated )

Multicluster Engine for Kubernetes 2.1.6 imagesMulticluster engine for Kubernetes provides the foundational componentsthat are necessary for the centralized management of multipleKubernetes-based clusters across data centers, public clouds, and privateclouds.You can use the engine to create new Red Hat OpenShift Container Platformclusters or to bring existing Kubernetes-based clusters under management byimporting them. After the clusters are managed, you can use the APIs thatare provided by the engine to distribute configuration based on placementpolicy.Jira issue addressed:ACM-3513: MCE 2.1.6 imagesSecurity fix(es): CVE-2022-25881 http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability

Remedy

For multicluster engine for Kubernetes, see the following documentation for details on how to install the images:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.6/html/multicluster_engine/multicluster_engine_overview#installing-while-connected-online-mce" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.6/html/multicluster_engine/multicluster_engine_overview#installing-while-connected-online-mce</a>
First published (updated )

Security Fix(es) CVE-2023-29017 vm2: Sandbox Escape CVE-2023-29199 vm2: Sandbox Escape CVE-2023-30547 vm2: Sandbox Escape when exception sanitization

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied, and that you are running Multicluster Engine for Kubernetes version 2.0.7.<br>See <a href="https://access.redhat.com/solutions/7007647" target="_blank">https://access.redhat.com/solutions/7007647</a> for instructions on how to apply this hotfix, as well as for information about when the hotfix has been<br>superseded by a permanent fix and should be removed.<br>Important: This hotfix is a temporary fix that will be supported until 30 days after the date when the next patch release of the product is released. After the 30-day period ends, you must either update to the latest patch release and remove this hotfix to continue receiving security updates and maintain support or upgrade to a newer feature release of the product.
First published (updated )

Security Fix(es) CVE-2023-29017 vm2: Sandbox Escape CVE-2023-29199 vm2: Sandbox Escape CVE-2023-30547 vm2: Sandbox Escape when exception sanitization

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied, and that you are running Multicluster Engine for Kubernetes version 2.1.5.<br>See <a href="https://access.redhat.com/solutions/7007647" target="_blank">https://access.redhat.com/solutions/7007647</a> for instructions on how to apply this hotfix, as well as for information about when the hotfix has been<br>superseded by a permanent fix and should be removed.<br>Important: This hotfix is a temporary fix that will be supported until 30 days after the date when the next patch release of the product is released. After the 30-day period ends, you must either update to the latest patch release and remove this hotfix to continue receiving security updates and maintain support or upgrade to a newer feature release of the product.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203