Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.4.3 security updates and bug fixes
🔗 CVE IDs covered (12)
📋 Description
CVE-2021-23518 — cached-path-relative: Prototype Pollution via the cache variable CVE-2021-23566 — nanoid: Information disclosure via valueOf() function CVE-2021-41190 — opencontainers: OCI manifest and index parsing confusion CVE-2021-43565 — golang.org/x/crypto: empty plaintext packet causes panic CVE-2022-0144 — nodejs-shelljs: improper privilege management CVE-2022-0155 — follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor CVE-2022-0235 — node-fetch: exposure of sensitive information to an unauthorized actor CVE-2022-0536 — follow-redirects: Exposure of Sensitive Information via Authorization Header leak CVE-2022-0778 — openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates CVE-2022-24450 — nats-server: misusing the "dynamically provisioned sandbox accounts" feature authenticated user can obtain the privileges of the System account CVE-2022-24778 — imgcrypt: Unauthorized access to encryted container image on a shared system due to missing check in CheckAuthorization() code path CVE-2022-27191 — golang: crash in a golang.org/x/crypto/ssh server
🔗 References (30)
- selfhttps://access.redhat.com/errata/RHSA-2022:1476
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.4/html/release_notes/index
- externalhttps://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.4/html-single/install/index#installing
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2024938
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2032128
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2033051
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039197
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2039820
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2042223
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2043535
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044556
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044591
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2048500
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2050853
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2052573
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053211
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053259
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053279
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056610
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2057249
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2059039
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2059954
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2062202
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064702
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2069368
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2074156
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2074543
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1476.json