{"id":21235,"date":"2022-03-04T19:28:08","date_gmt":"2022-03-04T16:28:08","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/166204\/RHSA-2022-0595-02.txt"},"modified":"2022-03-06T11:40:39","modified_gmt":"2022-03-06T08:10:39","slug":"red-hat-security-advisory-2022-0595-02","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-0595-02\/","title":{"rendered":"Red Hat Security Advisory 2022-0595-02"},"content":{"rendered":"<p dir=\"ltr\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p dir=\"ltr\">=====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p dir=\"ltr\">Synopsis: Important: Red Hat Advanced Cluster Management 2.3.6 security updates and bug fixes<br \/>\nAdvisory ID: RHSA-2022:0595-02<br \/>\nProduct: Red Hat ACM<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:0595<br \/>\nIssue date: 2022-02-22<br \/>\nUpdated on: 2022-03-04<br \/>\nCVE Names: CVE-2020-25704 CVE-2020-36322 CVE-2021-3521<br \/>\nCVE-2021-3712 CVE-2021-3872 CVE-2021-3918<br \/>\nCVE-2021-3984 CVE-2021-4019 CVE-2021-4034<br \/>\nCVE-2021-4122 CVE-2021-4155 CVE-2021-4192<br \/>\nCVE-2021-4193 CVE-2021-20321 CVE-2021-23566<br \/>\nCVE-2021-42574 CVE-2021-42739 CVE-2021-43565<br \/>\nCVE-2022-0155 CVE-2022-0185 CVE-2022-20612<br \/>\nCVE-2022-20617<br \/>\n=====================================================================<\/p>\n<p dir=\"ltr\">1. Summary:<\/p>\n<p dir=\"ltr\">Red Hat Advanced Cluster Management for Kubernetes 2.3.6 General<br \/>\nAvailability<br \/>\nrelease images, which provide security updates and bug fixes.<\/p>\n<p dir=\"ltr\">Red Hat Product Security has rated this update as having a security impact<br \/>\nof<br \/>\nModerate. A Common Vulnerability Scoring System (CVSS) base score, which<br \/>\ngives<br \/>\na detailed severity rating, is available for each vulnerability from the<br \/>\nCVE<br \/>\nlink(s) in the References section.<\/p>\n<p dir=\"ltr\">2. Description:<\/p>\n<p dir=\"ltr\">Red Hat Advanced Cluster Management for Kubernetes 2.3.6 images<\/p>\n<p dir=\"ltr\">Red Hat Advanced Cluster Management for Kubernetes provides the<br \/>\ncapabilities to address common challenges that administrators and site<br \/>\nreliability engineers face as they work across a range of public and<br \/>\nprivate cloud environments. Clusters and applications are all visible and<br \/>\nmanaged from a single console\u2014with security policy built in.<\/p>\n<p dir=\"ltr\">Red Hat Product Security has rated this update as having a security impact<br \/>\nof Important. A Common Vulnerability Scoring System (CVSS) base score,<br \/>\nwhich gives a detailed severity rating, is available for each vulnerability<br \/>\nfrom the CVE links in the References section.<\/p>\n<p dir=\"ltr\">This advisory contains the container images for Red Hat Advanced Cluster<br \/>\nManagement for Kubernetes, which provide some security fixes and bug fixes.<br \/>\nSee the following Release Notes documentation, which will be updated<br \/>\nshortly for this release, for additional details about this release:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/documentation\/en-us\/red_hat_advanced_cluster_management_for_kubernetes\/2.3\/html\/release_notes\/<\/p>\n<p dir=\"ltr\">Security updates:<\/p>\n<p dir=\"ltr\">* Nodejs-json-schema: Prototype pollution vulnerability (CVE-2021-3918)<\/p>\n<p dir=\"ltr\">* Nanoid: Information disclosure via valueOf() function (CVE-2021-23566)<\/p>\n<p dir=\"ltr\">* Golang.org\/x\/crypto: empty plaintext packet causes panic (CVE-2021-43565)<\/p>\n<p dir=\"ltr\">* Follow-redirects: Exposure of Private Personal Information to an<br \/>\nUnauthorized Actor (CVE-2022-0155)<\/p>\n<p dir=\"ltr\">Bug fixes:<\/p>\n<p dir=\"ltr\">* Inform ACM policy is not checking properly the node fields (BZ# 2015588)<\/p>\n<p dir=\"ltr\">* ImagePullPolicy is &#8220;Always&#8221; for multicluster-operators-subscription-rhel8<br \/>\nimage (BZ# 2021128)<\/p>\n<p dir=\"ltr\">* Traceback blocks reconciliation of helm repository hosted on AWS S3<br \/>\nstorage (BZ# 2021576)<\/p>\n<p dir=\"ltr\">* RHACM 2.3.6 images (BZ# 2029507)<\/p>\n<p dir=\"ltr\">* Console UI enabled SNO UI Options not displayed during cluster creating<br \/>\n(BZ# 2030002)<\/p>\n<p dir=\"ltr\">* Grc pod restarts for each new GET request to the Governance Policy Page<br \/>\n(BZ# 2037351)<\/p>\n<p dir=\"ltr\">* Clustersets do not appear in UI (BZ# 2049810)<\/p>\n<p dir=\"ltr\">3. Solution:<\/p>\n<p dir=\"ltr\">Before applying this update, make sure all previously released errata<br \/>\nrelevant to your system have been applied.<\/p>\n<p dir=\"ltr\">For details on how to apply this update, refer to:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/documentation\/en-us\/red_hat_advanced_cluster_management_for_kubernetes\/2.3\/html-single\/install\/index#installing<\/p>\n<p dir=\"ltr\">4. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p dir=\"ltr\">2015588 &#8211; Inform ACM policy is not checking properly the node fields<br \/>\n2021128 &#8211; imagePullPolicy is &#8220;Always&#8221; for multicluster-operators-subscription-rhel8 image<br \/>\n2021576 &#8211; traceback blocks reconciliation of helm repository hosted on AWS S3 storage<br \/>\n2024702 &#8211; CVE-2021-3918 nodejs-json-schema: Prototype pollution vulnerability<br \/>\n2029507 &#8211; RHACM 2.3.6 images<br \/>\n2030002 &#8211; Console UI enabled SNO UI Options not displayed during cluster creating<br \/>\n2030787 &#8211; CVE-2021-43565 golang.org\/x\/crypto: empty plaintext packet causes panic<br \/>\n2037351 &#8211; grc pod restarts for each new GET request to the Governance Policy Page<br \/>\n2044556 &#8211; CVE-2022-0155 follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor<br \/>\n2049810 &#8211; Clustersets do not appear in UI<br \/>\n2050853 &#8211; CVE-2021-23566 nanoid: Information disclosure via valueOf() function<\/p>\n<p dir=\"ltr\">5. References:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/security\/cve\/CVE-2020-25704<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-36322<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3521<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3712<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3872<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3918<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3984<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4019<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4034<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4122<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4155<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4192<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4193<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-20321<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-23566<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-42574<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-42739<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-43565<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0155<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0185<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-20612<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-20617<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#important<\/p>\n<p dir=\"ltr\">6. Contact:<\/p>\n<p dir=\"ltr\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p dir=\"ltr\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p dir=\"ltr\">iQIVAwUBYiGSAdzjgjWX9erEAQhcyg\/+JWkTD4CzyVTHwvwK5RW\/tiWQKmgEuQEK<br \/>\n3HRKdXDnhn428EkQLd\/pRfAvs1h\/7b7OxYxbcCYfijImM+mCcIFRxaFx7fc1TCac<br \/>\nc+0PetTXspkKbz7k+YqfNFXn3SFIG194thQreJE\/FDTwFr9YO+H915MsdUxAqxIT<br \/>\nU6sb4NrgeMBHysUsk9FcmTMETXYs2MximcfsZc8UNHXy1wNNpH8d+dPYKfY3Ew4I<br \/>\nlutUmP\/L1Zqz4cTpGeAAkwOR9doNVQTTNjRq3AT\/anrYWfSDlAYWKVQwajhG13Tu<br \/>\nzyTN+X2wbWEQ\/vlLKRgPpEQrlgSkmq5tP61jPGWcUkBRClUFmgJA6hDhOLhAhtqn<br \/>\nplupv0ajajWRwhFDFdpmVh4UzO2Wxmsf5B1Kuw36D+szPmbldm7IdE1UB1SWA1UG<br \/>\nWDc0Yz6Vxwk2E5PtIBFCpVdYU8\/wvOWSLM9E\/hH5JJ0LyPEmLGu2Bo2GoftDXdeK<br \/>\nZYf8XYYuINDOrTz3o3DQHHRUAKkZQE\/U+tTlK8CfqlXN3gCc+HpWhvUt3MH9EZX8<br \/>\nVVSru79\/CXUQcEk3IH3\/NgJmKXzK1WgR6cY3dLRgzbvKb22sTdygBftUmgkEKMx9<br \/>\nZJZl9D9\/tMnWqAUEm5iLu\/FXK8C42YtlTZFISb772hpAM3bZCQngvhewdp3pYjbV<br \/>\nqVz34lGi9mo=<br \/>\n=ODwI<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n<p dir=\"ltr\">&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Advanced Cluster Management 2.3.6 security updates and bug fixes Advisory ID: RHSA-2022:0595-02 Product: Red Hat ACM Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:0595 Issue date: 2022-02-22 Updated on: 2022-03-04 CVE Names: CVE-2020-25704 CVE-2020-36322 CVE-2021-3521 CVE-2021-3712 CVE-2021-3872 CVE-2021-3918 CVE-2021-3984 CVE-2021-4019 CVE-2021-4034 CVE-2021-4122 CVE-2021-4155 CVE-2021-4192 CVE-2021-4193 &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-21235","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/21235","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=21235"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/21235\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=21235"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=21235"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=21235"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}