{"id":21794,"date":"2022-03-15T20:59:52","date_gmt":"2022-03-15T17:59:52","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/166309\/RHSA-2022-0856-01.txt"},"modified":"2022-03-16T08:28:28","modified_gmt":"2022-03-16T04:58:28","slug":"red-hat-security-advisory-2022-0856-01","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-0856-01\/","title":{"rendered":"Red Hat Security Advisory 2022-0856-01"},"content":{"rendered":"<p dir=\"ltr\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p dir=\"ltr\">=====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p dir=\"ltr\">Synopsis: Moderate: Red Hat Advanced Cluster Management 2.2.11 security updates and bug fixes<br \/>\nAdvisory ID: RHSA-2022:0856-01<br \/>\nProduct: Red Hat ACM<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:0856<br \/>\nIssue date: 2022-03-14<br \/>\nCVE Names: CVE-2019-5827 CVE-2019-13750 CVE-2019-13751<br \/>\nCVE-2019-17594 CVE-2019-17595 CVE-2019-18218<br \/>\nCVE-2019-19603 CVE-2019-20838 CVE-2020-0465<br \/>\nCVE-2020-0466 CVE-2020-12762 CVE-2020-13435<br \/>\nCVE-2020-14155 CVE-2020-16135 CVE-2020-24370<br \/>\nCVE-2020-25709 CVE-2020-25710 CVE-2021-0920<br \/>\nCVE-2021-3200 CVE-2021-3426 CVE-2021-3445<br \/>\nCVE-2021-3521 CVE-2021-3564 CVE-2021-3572<br \/>\nCVE-2021-3573 CVE-2021-3580 CVE-2021-3712<br \/>\nCVE-2021-3752 CVE-2021-3800 CVE-2021-3872<br \/>\nCVE-2021-3984 CVE-2021-4019 CVE-2021-4122<br \/>\nCVE-2021-4155 CVE-2021-4192 CVE-2021-4193<br \/>\nCVE-2021-20231 CVE-2021-20232 CVE-2021-22876<br \/>\nCVE-2021-22898 CVE-2021-22925 CVE-2021-23434<br \/>\nCVE-2021-25214 CVE-2021-27645 CVE-2021-28153<br \/>\nCVE-2021-33560 CVE-2021-33574 CVE-2021-35942<br \/>\nCVE-2021-36084 CVE-2021-36085 CVE-2021-36086<br \/>\nCVE-2021-36087 CVE-2021-39241 CVE-2021-40346<br \/>\nCVE-2021-42574 CVE-2022-0155 CVE-2022-0185<br \/>\nCVE-2022-0330 CVE-2022-22942 CVE-2022-24407<br \/>\n=====================================================================<\/p>\n<p dir=\"ltr\">1. Summary:<\/p>\n<p dir=\"ltr\">Red Hat Advanced Cluster Management for Kubernetes 2.2.11 General<br \/>\nAvailability release images, which provide one or more container updates<br \/>\nand bug fixes.<\/p>\n<p dir=\"ltr\">Red Hat Product Security has rated this update as having a security impact<br \/>\nof Moderate. A Common Vulnerability Scoring System (CVSS) base score,<br \/>\nwhich gives a detailed severity rating, is available for each vulnerability<br \/>\nfrom the CVE link(s) in the References section.<\/p>\n<p dir=\"ltr\">2. Description:<\/p>\n<p dir=\"ltr\">Red Hat Advanced Cluster Management for Kubernetes 2.2.11 images<\/p>\n<p dir=\"ltr\">Red Hat Advanced Cluster Management for Kubernetes provides the<br \/>\ncapabilities to address common challenges that administrators and site<br \/>\nreliability engineers face as they work across a range of public and<br \/>\nprivate cloud environments.<\/p>\n<p dir=\"ltr\">Clusters and applications are all visible and managed from a single console<br \/>\n\u2014 with security policy built in.<\/p>\n<p dir=\"ltr\">This advisory contains the container images for Red Hat Advanced Cluster<br \/>\nManagement for Kubernetes, which provide security fixes, bug fixes and<br \/>\ncontainer upgrades. See the following Release Notes documentation, which<br \/>\nwill be updated shortly for this release, for additional details about this<br \/>\nrelease:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/documentation\/en-us\/red_hat_advanced_cluster_management_for_kubernetes\/2.2\/html\/release_notes\/<\/p>\n<p dir=\"ltr\">Security updates:<\/p>\n<p dir=\"ltr\">* object-path: Type confusion vulnerability can lead to a bypass of<br \/>\nCVE-2020-15256 (CVE-2021-23434)<\/p>\n<p dir=\"ltr\">* follow-redirects: Exposure of Private Personal Information to an<br \/>\nUnauthorized Actor (CVE-2022-0155)<\/p>\n<p dir=\"ltr\">Related bugs:<\/p>\n<p dir=\"ltr\">* RHACM 2.2.11 images (Bugzilla #2029508)<\/p>\n<p dir=\"ltr\">* ClusterImageSet has 4.5 which is not supported in ACM 2.2.10 (Bugzilla<br \/>\n#2030859)<\/p>\n<p dir=\"ltr\">3. Solution:<\/p>\n<p dir=\"ltr\">For Red Hat Advanced Cluster Management for Kubernetes, see the following<br \/>\ndocumentation, which will be updated shortly for this release, for<br \/>\nimportant instructions on how to upgrade your cluster and fully apply this<br \/>\nasynchronous errata update:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/documentation\/en-us\/red_hat_advanced_cluster_management_for_kubernetes\/2.2\/html\/release_notes\/index<\/p>\n<p dir=\"ltr\">For details on how to apply this update, refer to:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/documentation\/en-us\/red_hat_advanced_cluster_management_for_kubernetes\/2.2\/html-single\/install\/index#installing<\/p>\n<p dir=\"ltr\">4. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p dir=\"ltr\">1999810 &#8211; CVE-2021-23434 object-path: Type confusion vulnerability can lead to a bypass of CVE-2020-15256<br \/>\n2029508 &#8211; RHACM 2.2.11 images<br \/>\n2030859 &#8211; ClusterImageSet has 4.5 which is not supported in ACM 2.2.10<br \/>\n2044556 &#8211; CVE-2022-0155 follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor<\/p>\n<p dir=\"ltr\">5. References:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/security\/cve\/CVE-2019-5827<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2019-13750<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2019-13751<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2019-17594<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2019-17595<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2019-18218<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2019-19603<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2019-20838<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-0465<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-0466<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-12762<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-13435<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-14155<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-16135<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-24370<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-25709<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-25710<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-0920<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3200<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3426<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3445<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3521<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3564<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3572<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3573<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3580<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3712<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3752<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3800<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3872<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3984<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4019<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4122<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4155<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4192<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4193<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-20231<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-20232<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-22876<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-22898<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-22925<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-23434<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-25214<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-27645<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-28153<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-33560<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-33574<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-35942<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-36084<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-36085<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-36086<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-36087<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-39241<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-40346<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-42574<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0155<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0185<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0330<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-22942<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-24407<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#moderate<\/p>\n<p dir=\"ltr\">6. Contact:<\/p>\n<p dir=\"ltr\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p dir=\"ltr\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p dir=\"ltr\">iQIVAwUBYi+vA9zjgjWX9erEAQgTqA\/+J2DQsJewk+7lcFiIFg2V\/pbB8hc0RsP5<br \/>\nKbxZaTfWXw0Awen3M5xN9iwKH8v3zdgwKMiEdPi4STFxQEoyOATJ6f8n1tIrZtEv<br \/>\nyvR4I\/fCTeQZYZJDPuCaUl0xkL7yFMqKumSsVeTI\/zUWDQB5Ifv30KMX68FV2UUW<br \/>\n1T\/A0gMzdsCOGNh89jw1tvehqsxfUsBZbv2oqTJkSGsCeBQohuP58MHUeYXzGy5M<br \/>\nHAJhRfgJYTcQneRiUt3PIlH737YjkXW5vO4sYqmyS30SvEtT7HK12qnw9DuBk7bs<br \/>\ntPDvuNy2DFF7S3HARQAgsPDWJQvMBdu96Vm9XHsVHYs\/jSrj2B05wAwvYKp5J2q8<br \/>\nWhghlFQnU2QJvaDslUhnC6gz6CqHhU971qSSRWdyrdOLe+56pTg1g1YgJ2V46sIv<br \/>\nb6+9UIFMg0IgHuX9Ys\/MVMqXaNOv3tvglmzIGbGsFKE8afZ8FPykaWx1His8fg1b<br \/>\nLxDe8x1eBHDGL28Q4fPmTRcZ6kusODotZPnc8Bv1Y8z+EdDBATI7OZhx9ePpb1fL<br \/>\nGsXBkFvFEaVwTHKWwA3RwTV3uj2rUP7ZCHJuJSaVuZPxhlhY\/Q1bXZhSh5aY1oSk<br \/>\n+YUU9HGz9zRJMVHFiuFYp0zrrOFOGw7PGXUr4\/+\/pPFJkWOVApYvlsgx7DvkyYmB<br \/>\nXdiu19jyuh4=<br \/>\n=lH1Z<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Advanced Cluster Management 2.2.11 security updates and bug fixes Advisory ID: RHSA-2022:0856-01 Product: Red Hat ACM Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:0856 Issue date: 2022-03-14 CVE Names: CVE-2019-5827 CVE-2019-13750 CVE-2019-13751 CVE-2019-17594 CVE-2019-17595 CVE-2019-18218 CVE-2019-19603 CVE-2019-20838 CVE-2020-0465 CVE-2020-0466 CVE-2020-12762 CVE-2020-13435 CVE-2020-14155 CVE-2020-16135 CVE-2020-24370 CVE-2020-25709 &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-21794","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/21794","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=21794"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/21794\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=21794"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=21794"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=21794"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}