Important: Red Hat Service Interconnect 1.5.4 Release security update (images)
As a Kubernetes user, I cannot connect easily connect services from one cluster with services on another cluster. Red Hat Application Interconnect enables me to create a service network and it allows geographically distributed services to connect as if they were all running in the same site.
As a Kubernetes user, I cannot connect easily connect services from one cluster with services on another cluster. Red Hat Application Interconnect enables me to create a service network and it allows geographically distributed services to connect as if they were all running in the same site.
Important: Updated service-interconnect rhel9 container images for 1.8
Important: skupper-cli and skupper-router security update
A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated attacker in the adjacent cluster to view deployments in all namespaces in the cluster. This issue permits unauthorized viewing of information outside of the user's purview.
Moderate: Red Hat Service Interconnect security update
Low: Updated service-interconnect rhel9 container images for 1.4 LTS
Low: Security update for service-interconnect rhel9 container images
Low: Updated service-interconnect rhel9 container images for 1.4 LTS
Low: Updated service-interconnect rhel9 container images for 1.5
Security Fix(es): python: Path traversal on tempfile.TemporaryDirectory (CVE-2023-6597) python: The zipfile module is vulnerable to zip-bombs leading to denial of service (CVE-2024-0450) skupper: potential authentication bypass to skupper console via forged cookies (CVE-2024-6535) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Users of service-interconnect 1.5 rhel9 container images are advisedto upgrade to these updated images, which contain backported patches to correct security issues and fix bugs. Users of these images are also encouraged to rebuild all container images that depend on these images.You can find images updated by this advisory the in Red Hat Container Catalog
Security Fix(es): skupper-operator: privelege escalation via config map (CVE-2023-5056) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.