Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.4.4 security updates and bug fixes
🔗 CVE IDs covered (14)
📋 Description
CVE-2021-23555 — vm2: vulnerable to Sandbox Bypass
CVE-2021-43565 — golang.org/x/crypto: empty plaintext packet causes panic
CVE-2022-0155 — follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor
CVE-2022-0235 — node-fetch: exposure of sensitive information to an unauthorized actor
CVE-2022-0536 — follow-redirects: Exposure of Sensitive Information via Authorization Header leak
CVE-2022-0613 — urijs: Authorization Bypass Through User-Controlled Key
CVE-2022-1365 — cross-fetch: Exposure of Private Personal Information to an Unauthorized Actor
CVE-2022-21803 — nconf: Prototype pollution in memory store
CVE-2022-24450 — nats-server: misusing the "dynamically provisioned sandbox accounts" feature authenticated user can obtain the privileges of the System account
CVE-2022-24723 — urijs: Leading white space bypasses protocol validation
CVE-2022-24771 — node-forge: Signature verification leniency in checking digestAlgorithm structure can lead to signature forgery
CVE-2022-24772 — node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery
CVE-2022-24773 — node-forge: Signature verification leniency in checking DigestInfo structure
CVE-2022-24785 — Moment.js: Path traversal in moment.locale
🔗 References (27)
- selfhttps://access.redhat.com/errata/RHSA-2022:1681
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.3/html/release_notes/index
- externalhttps://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.3/html-single/install/index#installing
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1995380
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2008583
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2038250
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044556
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044591
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2052573
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053259
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053308
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2054114
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2055496
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2057761
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2058295
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2061958
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2062370
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2067387
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2067458
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2067461
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2072009
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2074689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2076133
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2077548
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1681.json