Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.4.2 security updates and bug fixes
🔗 CVE IDs covered (8)
📋 Description
CVE-2021-3807 — nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes CVE-2021-3918 — nodejs-json-schema: Prototype pollution vulnerability CVE-2021-22963 — fastify-static: open redirect via an URL with double slash followed by a domain CVE-2021-43565 — golang.org/x/crypto: empty plaintext packet causes panic CVE-2021-43816 — containerd: Unprivileged pod may bind mount any privileged regular file on disk CVE-2021-43858 — minio: user privilege escalation in AddUser() admin API CVE-2022-0235 — node-fetch: exposure of sensitive information to an unauthorized actor CVE-2022-24450 — nats-server: misusing the "dynamically provisioned sandbox accounts" feature authenticated user can obtain the privileges of the System account
🎯 Affected products200
- Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/acm-grafana-rhel8@sha256:7ad765f7a5a74974f8f7e1bd7c7607f91c19067bcd2f5042cef99a1d91adec53_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/acm-grafana-rhel8@sha256:e75f878531f55ddab73b1ba85bfd4216e9731e7530970309c98b02674f3657a6_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/acm-grafana-rhel8@sha256:e828bec08e8f241ca9d8a5ff73c93c6cbd739971af84f992fcb3c8082f76e803_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/acm-must-gather-rhel8@sha256:432fa46c31884249b7a119452cb85ade491de011eb5d838cd0b5831595d11351_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/acm-must-gather-rhel8@sha256:575c94019f8f90d03ed5f79e168b6e059b3adb56ad8b1e1805541bb40ba42df1_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/acm-must-gather-rhel8@sha256:891ee5829ed679b75f958d35b6a544f438f5e214b844a173c282ded1d176a7b0_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/acm-operator-bundle@sha256:127aeff2e13eeac87c9520ae415533810622bbe1a18555ded8eae09c5bbc8e56_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/acm-operator-bundle@sha256:b57d0e3d5bcb4baed92928a942323ce7bf11ee334b8d4b00948469ce04378836_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/acm-operator-bundle@sha256:e51b856ca8caffa6b9b1a7f38bad692fbfe53cdedb787a261f5d3b2edaa4cb16_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/agent-service-rhel8@sha256:68e4bf785e9e7b33862c8e63c2fcf1852dc2252d3c59b9e7e73c65e142d95b16_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/agent-service-rhel8@sha256:6f96c92a149ab8c99da14a172fd08136d341bab7b34c3a689c13617243999525_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/agent-service-rhel8@sha256:741604a600622a23298238ae77c8158a0f48a7078c1e9e11ce64e20482cc65d2_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/application-ui-rhel8@sha256:22ee444356dd999c4e5c191042835d5786f4fdfce2ec771dfac678af7f575d55_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/application-ui-rhel8@sha256:2b3ad388c0485e87b9450eadb24375e15d6cb6574382e5a66c4a59395a77f44f_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/application-ui-rhel8@sha256:f66de61a6a86e3f29ea3efa782313a98b5a9a97ea45e6fd31c186b030ffb9e04_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/assisted-image-service-rhel8@sha256:4473c90affee14d9e246542533e3667eb6107475da0c0429151cd4c0317ecf4d_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/assisted-image-service-rhel8@sha256:f329cfb7b49c76522263d25e3ed665ad4b28d2a1b72439607d1ce364c12f7dc0_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/assisted-installer-agent-rhel8@sha256:9a2d03fae3955d22bc0238e5a7f27d41f4b7c20231dbce50d4835c2e69826645_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/assisted-installer-reporter-rhel8@sha256:513da2c261c47b697a7045b5633900a6da254297536b2bf83ea8c42ca3ff213f_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/assisted-installer-reporter-rhel8@sha256:942d75d78c299ffa8f32d52150642cd8544bfca763df8d751a4da9b888702e5c_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/assisted-installer-rhel8@sha256:1f43259f4c720ea841c8e8889c83e0cd6ea46fa0d6dd1a224a57c8b1b90590c2_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/assisted-installer-rhel8@sha256:fc704563b786d0e0a23f407dd16a445abbc51f54f73c275e59e0962240635995_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/cert-policy-controller-rhel8@sha256:4deb60b66fdaf7b3e38ad5abaace000aa000f51b522b7f4878d5d960651116fb_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/cert-policy-controller-rhel8@sha256:69556bb78f47370e306f762f29c7d871272bd0fdaa8289fb4a5582eda05014e8_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/cert-policy-controller-rhel8@sha256:b9216c2370954d4ce43dfb21385abaaa66279eb89614673bfb764db720968f68_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/cluster-backup-rhel8-operator@sha256:4017c8393339e5107fc5218329a689c2e4c7e655f56dffe96c17ab504b26d08e_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/cluster-backup-rhel8-operator@sha256:89dc6255478d6fa18fe8998974b5d89899cbf57fe6ffe7182553cd2be2c0d204_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/cluster-backup-rhel8-operator@sha256:cdee6ef04071b6671c15e06874bbf52a36b12cabd156a68d21f5e471ddae763d_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- rhacm2/cluster-curator-controller-rhel8@sha256:5ce4139f81d16457aa745524a52edbf1e6b8ef7d0614b60837017e0b646cd5e2_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.4 for RHEL 8
- +170 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.4/html-single/install/index#installing Workaround: There is a workaround for this vulnerability: Changing passwords can be disabled by adding an explicit `Deny` rule to disable the API for users.
🔗 References (30)
- selfhttps://access.redhat.com/errata/RHSA-2022:0735
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2001668
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2007557
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2008592
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2012909
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2015152
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2023448
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2024702
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2028100
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2028196
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2028931
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2029506
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030005
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030379
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2032957
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2034198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2036057
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2036252
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039378
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2041015
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2042545
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2043519
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044434
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044591
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2050847
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2051797
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2052573
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_0735.json