Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.2.9 security, bug, and container updates
🔗 CVE IDs covered (11)
📋 Description
CVE-2021-3795 — semver-regex: inefficient regular expression complexity CVE-2021-23017 — nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name CVE-2021-23434 — object-path: Type confusion vulnerability can lead to a bypass of CVE-2020-15256 CVE-2021-23440 — nodejs-set-value: type confusion allows bypass of CVE-2019-10747 CVE-2021-32626 — redis: Lua scripts can overflow the heap-based Lua stack CVE-2021-32627 — redis: Integer overflow issue with Streams CVE-2021-32628 — redis: Integer overflow bug in the ziplist data structure CVE-2021-32672 — redis: Out of bounds read in lua debugger protocol parser CVE-2021-32675 — redis: Denial of service via Redis Standard Protocol (RESP) request CVE-2021-32687 — redis: Integer overflow issue with intsets CVE-2021-41099 — redis: Integer overflow issue with strings
🎯 Affected products79
- Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 7
- Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/acm-must-gather-rhel8@sha256:d97c9dd0de204f06b3c5966755f1563b41e95816fb01d4aa57122555c96a4f79_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/acm-operator-bundle@sha256:9bc036411ab5752bc17a476e7b937333d8d45b56995eea1e6f5a4d55e67bc82e_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/acmesolver-rhel8@sha256:3d96fe2aa1c0b1278ec43147c7ffe99fbf141524b0816d4e30053a18a08a229e_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/application-ui-rhel8@sha256:51568314b298a311f711abff22fa98ff8d35837438b589ff034ee0ebe4bdc326_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/cainjector-rhel8@sha256:10957b8af998c8a1df66e684fc4dc02cb98dce46021720f23013ece600682038_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/cert-manager-controller-rhel8@sha256:634f8ec868a039d1fdaea40e948298fbe4fcca3a679b8f2b8abb61625522393e_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/cert-manager-webhook-rhel8@sha256:3fe60aefe6e6b91d405a39b95c6eec08990d800af5d5cbcf2596269f8c45f2d1_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/cert-policy-controller-rhel8@sha256:420d44f311463cbab0b3bf3e84f3b9158703afbb82620c360d66532bcfb3c438_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/cert-policy-controller-rhel8@sha256:626d83118a97900d79eefd4658080c3f59169e592ff0d9506858f0c19688481d_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/clusterlifecycle-state-metrics-rhel8@sha256:241ca1bbeb90b03f3db45a2531f39b42b65f6d1c56e6f7874d83458522687a9c_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/config-policy-controller-rhel8@sha256:2ebb0f99256ff4050f9cef3e18157b6dff3218a518fde5f36a9e8fa0c16ef3eb_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/config-policy-controller-rhel8@sha256:3238ca55f433be8140881ee2102fac07eb5213cb6a85f5da09642652e4226824_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/configmap-watcher-rhel8@sha256:8b946b738ac66287f516626e856e478f8515e6f4e5c352be7ea555f2184e4ba6_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/console-api-rhel8@sha256:5df6085501373dccfa902809e84ebc8b8b05e147ce55426b2c16b3d23ac1fc02_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/console-header-rhel8@sha256:99292da1c32de7297daeda4d733fa7fd9a38ff28b2502f4f4598ec4bba69ec30_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/console-rhel8@sha256:f0fa79072e45abdbf72a488092147d956f9750b3ea8701e4f6579be140a98418_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/endpoint-component-rhel8-operator@sha256:a43d7f412474af84303d3dd4446ad9fadffb06cde2f6a2dfd9d93a273d70b5bc_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/endpoint-component-rhel8-operator@sha256:b0e3444190b7c8b0093892de4914a0937020ce638ca40514927e7effe929ecb5_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/endpoint-monitoring-rhel8-operator@sha256:385861e33f84796dc711d533bb3ec176c5ddbe5aae4c11a87152047a8b6dc9c0_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/endpoint-monitoring-rhel8-operator@sha256:3de50f77454020e4f1799c42e326bf166526fa2d69bb04d0a844792e7af94ad0_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/endpoint-rhel8-operator@sha256:7264db47896740062ec1a20e555071354234cc7ceffcce9ab43f80d6b690d376_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/governance-policy-propagator-rhel8@sha256:2d107d25cc98268f68896180bc43b2e757a66bc0b5ecc99327f3c85206c2fcd8_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/governance-policy-spec-sync-rhel8@sha256:44c22235f4371cd2811db3c5c8ce7be9af3942cf4c69ef43506b404817ef3c68_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/governance-policy-spec-sync-rhel8@sha256:7c97f4d80817258abf112a0d14c87b79648f2987a3df7f37f17d1e0ced03296b_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/governance-policy-status-sync-rhel8@sha256:5c3da6dc048baae8ac9ef7e3c916f6a269266807bc46aa79a49e68557cc686b9_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/governance-policy-status-sync-rhel8@sha256:75ee9a2af8913cfa8ef233aaeccaa23bf6b9897ecc70007aa2582d98828c14e5_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/governance-policy-template-sync-rhel8@sha256:3f0db2406add90fcd2e0f28d77bdb171e7e04a648b0bcf8c390cb6e5f2b10ca6_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- rhacm2/governance-policy-template-sync-rhel8@sha256:7f03fe741bfb5b04ec67e5077252b832922c1ae8e4b5b2bf2474a082161ab9e6_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.2 for RHEL 8
- +49 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.2/html-single/install/index#installing Workaround: Prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands. Please see https://redis.io/topics/acl for more information on how to do this. Workaround: The flaw can be mitigated by disallowing usage of the CONFIG SET command via ACL configuration. This will prevent clients from setting the `proto-max-bulk-len` configuration parameter. Please see https://redis.io/topics/acl for more information on how to do this. Workaround: The flaw can be mitigated by disallowing usage of the CONFIG SET command via ACL configuration. This will prevent clients from setting the above configuration parameters. Please see https://redis.io/topics/acl for more information on how to do this. Workaround: Prevent unauthenticated users from connecting to Redis by using network access control tools (e.g., firewalls) or enabling TLS and requiring users to authenticate using client side certificates. Workaround: The flaw can be mitigated by disallowing usage of the CONFIG SET command via ACL configuration. This will prevent clients from setting the `set-max-intset-entries` configuration parameter. Please see https://redis.io/topics/acl for more information on how to do this.
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2021:3873
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1963121
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999601
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999810
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2010991
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011004
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011010
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011017
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011020
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3873.json