RHSA-2024:5453HighCVSS 8.8
Red Hat Security Advisory: Fence Agents Remediation 0.4.1 - Security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-5651 — fence-agents-remediation: Fence Agent Command Line Options Leads to Remote Code Execution
🎯 Affected products3
- Fence Agents Remediation 0.4 for RHEL 8
- workload-availability/fence-agents-remediation-operator-bundle@sha256:f5dda99364d07df3a3680a2d7031c27df071c8e80746b1ececb5487240e9bbb0_amd64 as a component of Fence Agents Remediation 0.4 for RHEL 8
- workload-availability/fence-agents-remediation-rhel8-operator@sha256:b0abc89cdccc6fe6510143d8a2440fd277e69b47f83cfda3e61782f50f88a988_amd64 as a component of Fence Agents Remediation 0.4 for RHEL 8
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Do not allow unprivileged users create FenceAgentsRemediation and FenceAgentsRemediationTemplate resources.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:5453
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2290540
- externalhttps://issues.redhat.com/browse/ECOPROJECT-2024
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5453.json