RHSA-2025:22683MediumCVSS 7.5
Red Hat Security Advisory: multicluster engine for Kubernetes v2.7.7 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2022-21698 — prometheus/client_golang: Denial of service using InstrumentHandlerCounter CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2025-7195 — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd CVE-2025-22871 — net/http: Request smuggling due to acceptance of invalid chunked data in net/http
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2025:22683
- externalhttps://access.redhat.com/security/cve/CVE-2022-21698
- externalhttps://access.redhat.com/security/cve/CVE-2024-24786
- externalhttps://access.redhat.com/security/cve/CVE-2025-22871
- externalhttps://access.redhat.com/security/cve/CVE-2025-7195
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_22683.json