{"id":25592,"date":"2022-06-09T20:28:27","date_gmt":"2022-06-09T16:28:27","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167459\/RHSA-2022-4956-01.txt"},"modified":"2022-06-14T11:59:40","modified_gmt":"2022-06-14T07:29:40","slug":"red-hat-security-advisory-2022-4956-01","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-4956-01\/","title":{"rendered":"Red Hat Security Advisory 2022-4956-01"},"content":{"rendered":"<p dir=\"ltr\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p dir=\"ltr\">=====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p dir=\"ltr\">Synopsis: Important: Red Hat Advanced Cluster Management 2.5 security updates, images, and bug fixes<br \/>\nAdvisory ID: RHSA-2022:4956-01<br \/>\nProduct: Red Hat ACM<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:4956<br \/>\nIssue date: 2022-06-08<br \/>\nCVE Names: CVE-2020-0404 CVE-2020-4788 CVE-2020-13974<br \/>\nCVE-2020-19131 CVE-2020-27820 CVE-2021-0941<br \/>\nCVE-2021-3612 CVE-2021-3634 CVE-2021-3669<br \/>\nCVE-2021-3737 CVE-2021-3743 CVE-2021-3744<br \/>\nCVE-2021-3752 CVE-2021-3759 CVE-2021-3764<br \/>\nCVE-2021-3772 CVE-2021-3773 CVE-2021-3918<br \/>\nCVE-2021-4002 CVE-2021-4037 CVE-2021-4083<br \/>\nCVE-2021-4157 CVE-2021-4189 CVE-2021-4197<br \/>\nCVE-2021-4203 CVE-2021-20322 CVE-2021-21781<br \/>\nCVE-2021-26401 CVE-2021-29154 CVE-2021-37159<br \/>\nCVE-2021-41190 CVE-2021-41864 CVE-2021-42739<br \/>\nCVE-2021-43056 CVE-2021-43389 CVE-2021-43565<br \/>\nCVE-2021-43816 CVE-2021-43858 CVE-2021-43976<br \/>\nCVE-2021-44733 CVE-2021-45485 CVE-2021-45486<br \/>\nCVE-2022-0001 CVE-2022-0002 CVE-2022-0235<br \/>\nCVE-2022-0286 CVE-2022-0322 CVE-2022-0778<br \/>\nCVE-2022-1011 CVE-2022-21803 CVE-2022-23806<br \/>\nCVE-2022-24450 CVE-2022-24778 CVE-2022-24785<br \/>\nCVE-2022-27191 CVE-2022-29810<br \/>\n=====================================================================<\/p>\n<p dir=\"ltr\">1. Summary:<\/p>\n<p dir=\"ltr\">Red Hat Advanced Cluster Management for Kubernetes 2.5.0 is now generally<br \/>\navailable.<\/p>\n<p dir=\"ltr\">Red Hat Product Security has rated this update as having a security impact<br \/>\nof Important. A Common Vulnerability Scoring System (CVSS) base score,<br \/>\nwhich<br \/>\ngives a detailed severity rating, is available for each vulnerability from<br \/>\nthe CVE links in the References section.<\/p>\n<p dir=\"ltr\">2. Description:<\/p>\n<p dir=\"ltr\">Red Hat Advanced Cluster Management for Kubernetes 2.5.0 images<\/p>\n<p dir=\"ltr\">Red Hat Advanced Cluster Management for Kubernetes provides the<br \/>\ncapabilities to address common challenges that administrators and site<br \/>\nreliability engineers face as they work across a range of public and<br \/>\nprivate cloud environments. Clusters and applications are all visible and<br \/>\nmanaged from a single console\u2014with security policy built in.<\/p>\n<p dir=\"ltr\">This advisory contains the container images for Red Hat Advanced Cluster<br \/>\nManagement for Kubernetes, which fix several bugs and security issues. See<br \/>\nthe following Release Notes documentation, which will be updated shortly<br \/>\nfor this release, for additional details about this release:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/documentation\/en-us\/red_hat_advanced_cluster_management_for_kubernetes\/2.5\/html\/release_notes\/<\/p>\n<p dir=\"ltr\">Security fixes:<\/p>\n<p dir=\"ltr\">* nodejs-json-schema: Prototype pollution vulnerability (CVE-2021-3918)<\/p>\n<p dir=\"ltr\">* containerd: Unprivileged pod may bind mount any privileged regular file<br \/>\non disk (CVE-2021-43816)<\/p>\n<p dir=\"ltr\">* minio: user privilege escalation in AddUser() admin API (CVE-2021-43858)<\/p>\n<p dir=\"ltr\">* openssl: Infinite loop in BN_mod_sqrt() reachable when parsing<br \/>\ncertificates (CVE-2022-0778)<\/p>\n<p dir=\"ltr\">* imgcrypt: Unauthorized access to encryted container image on a shared<br \/>\nsystem due to missing check in CheckAuthorization() code path<br \/>\n(CVE-2022-24778)<\/p>\n<p dir=\"ltr\">* golang.org\/x\/crypto: empty plaintext packet causes panic (CVE-2021-43565)<\/p>\n<p dir=\"ltr\">* node-fetch: exposure of sensitive information to an unauthorized actor<br \/>\n(CVE-2022-0235)<\/p>\n<p dir=\"ltr\">* nconf: Prototype pollution in memory store (CVE-2022-21803)<\/p>\n<p dir=\"ltr\">* golang: crypto\/elliptic IsOnCurve returns true for invalid field elements<br \/>\n(CVE-2022-23806)<\/p>\n<p dir=\"ltr\">* nats-server: misusing the &#8220;dynamically provisioned sandbox accounts&#8221;<br \/>\nfeature authenticated user can obtain the privileges of the System account<br \/>\n(CVE-2022-24450)<\/p>\n<p dir=\"ltr\">* Moment.js: Path traversal in moment.locale (CVE-2022-24785)<\/p>\n<p dir=\"ltr\">* golang: crash in a golang.org\/x\/crypto\/ssh server (CVE-2022-27191)<\/p>\n<p dir=\"ltr\">* go-getter: writes SSH credentials into logfile, exposing sensitive<br \/>\ncredentials to local uses (CVE-2022-29810)<\/p>\n<p dir=\"ltr\">* opencontainers: OCI manifest and index parsing confusion (CVE-2021-41190)<\/p>\n<p dir=\"ltr\">Bug fixes:<\/p>\n<p dir=\"ltr\">* RFE Copy secret with specific secret namespace, name for source and name,<br \/>\nnamespace and cluster label for target (BZ# 2014557)<\/p>\n<p dir=\"ltr\">* RHACM 2.5.0 images (BZ# 2024938)<\/p>\n<p dir=\"ltr\">* [UI] When you delete host agent from infraenv no confirmation message<br \/>\nappear (Are you sure you want to delete x?) (BZ#2028348)<\/p>\n<p dir=\"ltr\">* Clusters are in &#8216;Degraded&#8217; status with upgrade env due to obs-controller<br \/>\nnot working properly (BZ# 2028647)<\/p>\n<p dir=\"ltr\">* create cluster pool -&gt; choose infra type, As a result infra providers<br \/>\ndisappear from UI. (BZ# 2033339)<\/p>\n<p dir=\"ltr\">* Restore\/backup shows up as Validation failed but the restore backup<br \/>\nstatus in ACM shows success (BZ# 2034279)<\/p>\n<p dir=\"ltr\">* Observability &#8211; OCP 311 node role are not displayed completely (BZ#<br \/>\n2038650)<\/p>\n<p dir=\"ltr\">* Documented uninstall procedure leaves many leftovers (BZ# 2041921)<\/p>\n<p dir=\"ltr\">* infrastructure-operator pod crashes due to insufficient privileges in ACM<br \/>\n2.5 (BZ# 2046554)<\/p>\n<p dir=\"ltr\">* Acm failed to install due to some missing CRDs in operator (BZ# 2047463)<\/p>\n<p dir=\"ltr\">* Navigation icons no longer showing in ACM 2.5 (BZ# 2051298)<\/p>\n<p dir=\"ltr\">* ACM home page now includes \/home\/ in url (BZ# 2051299)<\/p>\n<p dir=\"ltr\">* proxy heading in Add Credential should be capitalized (BZ# 2051349)<\/p>\n<p dir=\"ltr\">* ACM 2.5 tries to create new MCE instance when install on top of existing<br \/>\nMCE 2.0 (BZ# 2051983)<\/p>\n<p dir=\"ltr\">* Create Policy button does not work and user cannot use console to create<br \/>\npolicy (BZ# 2053264)<\/p>\n<p dir=\"ltr\">* No cluster information was displayed after a policyset was created (BZ#<br \/>\n2053366)<\/p>\n<p dir=\"ltr\">* Dynamic plugin update does not take effect in Firefox (BZ# 2053516)<\/p>\n<p dir=\"ltr\">* Replicated policy should not be available when creating a Policy Set (BZ#<br \/>\n2054431)<\/p>\n<p dir=\"ltr\">* Placement section in Policy Set wizard does not reset when users click<br \/>\n&#8220;Back&#8221; to re-configured placement (BZ# 2054433)<\/p>\n<p dir=\"ltr\">3. Solution:<\/p>\n<p dir=\"ltr\">For Red Hat Advanced Cluster Management for Kubernetes, see the following<br \/>\ndocumentation, which will be updated shortly for this release, for<br \/>\nimportant<br \/>\ninstructions on installing this release:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/documentation\/en-us\/red_hat_advanced_cluster_management_for_kubernetes\/2.5\/html-single\/install\/index#installing<\/p>\n<p dir=\"ltr\">4. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p dir=\"ltr\">2014557 &#8211; RFE Copy secret with specific secret namespace, name for source and name, namespace and cluster label for target<br \/>\n2024702 &#8211; CVE-2021-3918 nodejs-json-schema: Prototype pollution vulnerability<br \/>\n2024938 &#8211; CVE-2021-41190 opencontainers: OCI manifest and index parsing confusion<br \/>\n2028224 &#8211; RHACM 2.5.0 images<br \/>\n2028348 &#8211; [UI] When you delete host agent from infraenv no confirmation message appear (Are you sure you want to delete x?)<br \/>\n2028647 &#8211; Clusters are in &#8216;Degraded&#8217; status with upgrade env due to obs-controller not working properly<br \/>\n2030787 &#8211; CVE-2021-43565 golang.org\/x\/crypto: empty plaintext packet causes panic<br \/>\n2033339 &#8211; create cluster pool -&gt; choose infra type , As a result infra providers disappear from UI.<br \/>\n2034279 &#8211; Restore\/backup shows up as Validation failed but the restore backup status in ACM shows success<br \/>\n2036252 &#8211; CVE-2021-43858 minio: user privilege escalation in AddUser() admin API<br \/>\n2038650 &#8211; Observability &#8211; OCP 311 node role are not displayed completely<br \/>\n2041921 &#8211; Documented uninstall procedure leaves many leftovers<br \/>\n2044434 &#8211; CVE-2021-43816 containerd: Unprivileged pod may bind mount any privileged regular file on disk<br \/>\n2044591 &#8211; CVE-2022-0235 node-fetch: exposure of sensitive information to an unauthorized actor<br \/>\n2046554 &#8211; infrastructure-operator pod crashes due to insufficient privileges in ACM 2.5<br \/>\n2047463 &#8211; Acm failed to install due to some missing CRDs in operator<br \/>\n2051298 &#8211; Navigation icons no longer showing in ACM 2.5<br \/>\n2051299 &#8211; ACM home page now includes \/home\/ in url<br \/>\n2051349 &#8211; proxy heading in Add Credential should be capitalized<br \/>\n2051983 &#8211; ACM 2.5 tries to create new MCE instance when install on top of existing MCE 2.0<br \/>\n2052573 &#8211; CVE-2022-24450 nats-server: misusing the &#8220;dynamically provisioned sandbox accounts&#8221; feature authenticated user can obtain the privileges of the System account<br \/>\n2053264 &#8211; Create Policy button does not work and user cannot use console to create policy<br \/>\n2053366 &#8211; No cluster information was displayed after a policyset was created<br \/>\n2053429 &#8211; CVE-2022-23806 golang: crypto\/elliptic IsOnCurve returns true for invalid field elements<br \/>\n2053516 &#8211; Dynamic plugin update does not take effect in Firefox<br \/>\n2054431 &#8211; Replicated policy should not be available when creating a Policy Set<br \/>\n2054433 &#8211; Placement section in Policy Set wizard does not reset when users click &#8220;Back&#8221; to re-configured placement<br \/>\n2054772 &#8211; credentialName is not parsed correctly in UI notifications\/alerts when creating\/updating a discovery config<br \/>\n2054860 &#8211; Cluster overview page crashes for on-prem cluster<br \/>\n2055333 &#8211; Unable to delete assisted-service operator<br \/>\n2055900 &#8211; If MCH is installed on existing MCE and both are in multicluster-engine namespace , uninstalling MCH terminates multicluster-engine namespace<br \/>\n2056485 &#8211; [UI] In infraenv detail the host list don&#8217;t have pagination<br \/>\n2056701 &#8211; Non platform install fails agentclusterinstall CRD is outdated in rhacm2.5<br \/>\n2057060 &#8211; [CAPI] Unable to create ClusterDeployment due to service account restrictions (ACM + Bundled Assisted)<br \/>\n2058435 &#8211; Label cluster.open-cluster-management.io\/backup-cluster stamped &#8216;unknown&#8217; for velero backups<br \/>\n2059779 &#8211; spec.nodeSelector is missing in MCE instance created by MCH upon installing ACM on infra nodes<br \/>\n2059781 &#8211; Policy UI crashes when viewing details of configuration policies for backupschedule that does not exist<br \/>\n2060135 &#8211; [assisted-install] agentServiceConfig left orphaned after uninstalling ACM<br \/>\n2060151 &#8211; Policy set of the same name cannot be re-created after the previous one has been deleted<br \/>\n2060230 &#8211; [UI] Delete host modal has incorrect host&#8217;s name populated<br \/>\n2060309 &#8211; multiclusterhub stuck in installing on &#8220;ManagedClusterConditionAvailable&#8221; [intermittent]\n2060469 &#8211; The development branch of the Submariner addon deploys 0.11.0, not 0.12.0<br \/>\n2060550 &#8211; MCE installation hang due to no console-mce-console deployment available<br \/>\n2060603 &#8211; prometheus doesn&#8217;t display managed clusters<br \/>\n2060831 &#8211; Observability &#8211; prometheus-operator failed to start on *KS<br \/>\n2060934 &#8211; Cannot provision AWS OCP 4.9 cluster from Power Hub<br \/>\n2061260 &#8211; The value of the policyset placement should be filtered space when input cluster label expression<br \/>\n2061311 &#8211; Cleanup of installed spoke clusters hang on deletion of spoke namespace<br \/>\n2061659 &#8211; the network section in create cluster -&gt; Networking include the brace in the network title<br \/>\n2061798 &#8211; [ACM 2.5] The service of Cluster Proxy addon was missing<br \/>\n2061838 &#8211; ACM component subscriptions are removed when enabling spec.disableHubSelfManagement in MCH<br \/>\n2062009 &#8211; No name validation is performed on Policy and Policy Set Wizards<br \/>\n2062022 &#8211; cluster.open-cluster-management.io\/backup-cluster of velero schedules should populate the corresponding hub clusterID<br \/>\n2062025 &#8211; No validation is done on yaml&#8217;s format or content in Policy and Policy Set wizards<br \/>\n2062202 &#8211; CVE-2022-0778 openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates<br \/>\n2062337 &#8211; velero schedules get re-created after the backupschedule is in &#8216;BackupCollision&#8217; phase<br \/>\n2062462 &#8211; Upgrade to 2.5 hang due to irreconcilable errors of grc-sub and search-prod-sub in MCH<br \/>\n2062556 &#8211; Always return the policyset page after created the policy from UI<br \/>\n2062787 &#8211; Submariner Add-on UI does not indicate on Broker error<br \/>\n2063055 &#8211; User with cluserrolebinding of open-cluster-management:cluster-manager-admin role can&#8217;t see policies and clusters page<br \/>\n2063341 &#8211; Release imagesets are missing in the console for ocp 4.10<br \/>\n2063345 &#8211; Application Lifecycle- UI shows white blank page when the page is Refreshed<br \/>\n2063596 &#8211; claim clusters from clusterpool throws errors<br \/>\n2063599 &#8211; Update the message in clusterset -&gt; clusterpool page since we did not allow to add clusterpool to clusterset by resourceassignment<br \/>\n2063697 &#8211; Observability &#8211; MCOCR reports object-storage secret without AWS access_key in STS enabled env<br \/>\n2064231 &#8211; Can not clean the instance type for worker pool when create the clusters<br \/>\n2064247 &#8211; prefer UI can add the architecture type when create the cluster<br \/>\n2064392 &#8211; multicloud oauth-proxy failed to log users in on web<br \/>\n2064477 &#8211; Click at &#8220;Edit Policy&#8221; for each policy leads to a blank page<br \/>\n2064509 &#8211; No option to view the ansible job details and its history in the Automation wizard after creation of the automation job<br \/>\n2064516 &#8211; Unable to delete an automation job of a policy<br \/>\n2064528 &#8211; Columns of Policy Set, Status and Source on Policy page are not sortable<br \/>\n2064535 &#8211; Different messages on the empty pages of Overview and Clusters when policy is disabled<br \/>\n2064702 &#8211; CVE-2022-27191 golang: crash in a golang.org\/x\/crypto\/ssh server<br \/>\n2064722 &#8211; [Tracker] [DR][ACM 2.5] Applications are not getting deployed on managed cluster<br \/>\n2064899 &#8211; Failed to provision openshift 4.10 on bare metal<br \/>\n2065436 &#8211; &#8220;Filter&#8221; drop-down list does not show entries of the policies that have no top-level remediation specified<br \/>\n2066198 &#8211; Issues about disabled policy from UI<br \/>\n2066207 &#8211; The new created policy should be always shown up on the first line<br \/>\n2066333 &#8211; The message was confuse when the cluster status is Running<br \/>\n2066383 &#8211; MCE install failing on proxy disconnected environment<br \/>\n2066433 &#8211; Logout not working for ACM 2.5<br \/>\n2066464 &#8211; console-mce-console pods throw ImagePullError after upgrading to ocp 4.10<br \/>\n2066475 &#8211; User with view-only rolebinding should not be allowed to create policy, policy set and automation job<br \/>\n2066544 &#8211; The search box can&#8217;t work properly in Policies page<br \/>\n2066594 &#8211; RFE: Can&#8217;t open the helm source link of the backup-restore-enabled policy from UI<br \/>\n2066650 &#8211; minor issues in cluster curator due to the startup throws errors<br \/>\n2066751 &#8211; the image repo of application-manager did not updated to use the image repo in MCE\/MCH configuration<br \/>\n2066834 &#8211; Hibernating cluster(s) in cluster pool stuck in &#8216;Stopping&#8217; status after restore activation<br \/>\n2066842 &#8211; cluster pool credentials are not backed up<br \/>\n2066914 &#8211; Unable to remove cluster value during configuration of the label expressions for policy and policy set<br \/>\n2066940 &#8211; Validation fired out for https proxy when the link provided not starting with https<br \/>\n2066965 &#8211; No message is displayed in Policy Wizard to indicate a policy externally managed<br \/>\n2066979 &#8211; MIssing groups in policy filter options comparing to previous RHACM version<br \/>\n2067053 &#8211; I was not able to remove the image mirror content when create the cluster<br \/>\n2067067 &#8211; Can&#8217;t filter the cluster info when clicked the cluster in the Placement section<br \/>\n2067207 &#8211; Bare metal asset secrets are not backed up<br \/>\n2067465 &#8211; Categories,Standards, and Controls annotations are not updated after user has deleted a selected template<br \/>\n2067713 &#8211; Columns on policy&#8217;s &#8220;Results&#8221; are not sort-able as in previous release<br \/>\n2067728 &#8211; Can&#8217;t search in the policy creation or policyset creation Yaml editor<br \/>\n2068304 &#8211; Application Lifecycle- Replicasets arent showing the logs console in Topology<br \/>\n2068309 &#8211; For policy wizard in dynamics plugin environment, buttons at the bottom should be sticky and the contents of the Policy should scroll<br \/>\n2068312 &#8211; Application Lifecycle &#8211; Argo Apps are not showing overview details and topology after upgrading from 2.4<br \/>\n2068313 &#8211; Application Lifecycle &#8211; Refreshing overview page leads to a blank page<br \/>\n2068328 &#8211; A cluster&#8217;s &#8220;View history&#8221; page should not contain all clusters&#8217; violations history<br \/>\n2068387 &#8211; Observability &#8211; observability operator always CrashLoopBackOff in FIPS upgrading hub<br \/>\n2068993 &#8211; Observability &#8211; Node list is not filtered according to nodeType on OCP 311 dashboard<br \/>\n2069329 &#8211; config-policy-controller addon with &#8220;Unknown&#8221; status in OCP 3.11 managed cluster after upgrade hub to 2.5<br \/>\n2069368 &#8211; CVE-2022-24778 imgcrypt: Unauthorized access to encryted container image on a shared system due to missing check in CheckAuthorization() code path<br \/>\n2069469 &#8211; Status of unreachable clusters is not reported in several places on GRC panels<br \/>\n2069615 &#8211; The YAML editor can&#8217;t work well when login UI using dynamic console plugin<br \/>\n2069622 &#8211; No validation for policy template&#8217;s name<br \/>\n2069698 &#8211; After claim a cluster from clusterpool, the cluster pages become very very slow<br \/>\n2069867 &#8211; Error occurs when trying to edit an application set\/subscription<br \/>\n2069870 &#8211; ACM\/MCE Dynamic Plugins &#8211; 404: Page Not Found Error Occurs &#8211; intermittent crashing<br \/>\n2069875 &#8211; Cluster secrets are not being created in the managed cluster&#8217;s namespace<br \/>\n2069895 &#8211; Application Lifecycle &#8211; Replicaset and Pods gives error messages when Yaml is selected on sidebar<br \/>\n2070203 &#8211; Blank Application is shown when editing an Application with AnsibleJobs<br \/>\n2070782 &#8211; Failed Secret Propagation to the Same Namespace as the AnsibleJob CR<br \/>\n2070846 &#8211; [ACM 2.5] Can&#8217;t re-add the default clusterset label after removing it from a managedcluster on BM SNO hub<br \/>\n2071066 &#8211; Policy set details panel does not work when deployed into namespace different than &#8220;default&#8221;<br \/>\n2071173 &#8211; Configured RunOnce automation job is not displayed although the policy has no violation<br \/>\n2071191 &#8211; MIssing title on details panel after clicking &#8220;view details&#8221; of a policy set card<br \/>\n2071769 &#8211; Placement must be always configured or error is reported when creating a policy<br \/>\n2071818 &#8211; ACM logo not displayed in About info modal<br \/>\n2071869 &#8211; Topology includes the status of local cluster resources when Application is only deployed to managed cluster<br \/>\n2072009 &#8211; CVE-2022-24785 Moment.js: Path traversal in moment.locale<br \/>\n2072097 &#8211; Local Cluster is shown as Remote on the Application Overview Page and Single App Overview Page<br \/>\n2072104 &#8211; Inconsistent &#8220;Not Deployed&#8221; Icon Used Between 2.4 and 2.5 as well as the Overview and Topology<br \/>\n2072177 &#8211; Cluster Resource Status is showing App Definition Statuses as well<br \/>\n2072227 &#8211; Sidebar Statuses Need to Be Updated to Reflect Cluster List and Cluster Resource Statuses<br \/>\n2072231 &#8211; Local Cluster not included in the appsubreport for Helm Applications Deployed on All Clusters<br \/>\n2072334 &#8211; Redirect URL is now to the details page after created a policy<br \/>\n2072342 &#8211; Shows &#8220;NaN%&#8221; in the ring chart when add the disabled policy into policyset and view its details<br \/>\n2072350 &#8211; CRD Deployed via Application Console does not have correct deployment status and spelling<br \/>\n2072359 &#8211; Report the error when editing compliance type in the YAML editor and then submit the changes<br \/>\n2072504 &#8211; The policy has violations on the failed managed cluster<br \/>\n2072551 &#8211; URL dropdown is not being rendered with an Argo App with a new URL<br \/>\n2072773 &#8211; When a channel is deleted and recreated through the App Wizard, application creation stalls and warning pops up<br \/>\n2072824 &#8211; The edit\/delete policyset button should be greyed when using viewer check<br \/>\n2072829 &#8211; When Argo App with jsonnet object is deployed, topology and cluster status would fail to display the correct statuses.<br \/>\n2073179 &#8211; Policy controller was unable to retrieve violation status in for an OCP 3.11 managed cluster on ARM hub<br \/>\n2073330 &#8211; Observabilityy &#8211; memory usage data are not collected even collect rule is fired on SNO<br \/>\n2073355 &#8211; Get blank page when click policy with unknown status in Governance -&gt; Overview page<br \/>\n2073508 &#8211; Thread responsible to get insights data from *ks clusters is broken<br \/>\n2073557 &#8211; appsubstatus is not deleted for Helm applications when changing between 2 managed clusters<br \/>\n2073726 &#8211; Placement of First Subscription gets overlapped by the Cluster Node in Application Topology<br \/>\n2073739 &#8211; Console\/App LC &#8211; Error message saying resource conflict only shows up in standalone ACM but not in Dynamic plugin<br \/>\n2073740 &#8211; Console\/App LC- Apps are deployed even though deployment do not proceed because of &#8220;resource conflict&#8221; error<br \/>\n2074178 &#8211; Editing Helm Argo Applications does not Prune Old Resources<br \/>\n2074626 &#8211; Policy placement failure during ZTP SNO scale test<br \/>\n2074689 &#8211; CVE-2022-21803 nconf: Prototype pollution in memory store<br \/>\n2074803 &#8211; The import cluster YAML editor shows the klusterletaddonconfig was required on MCE portal<br \/>\n2074937 &#8211; UI allows creating cluster even when there are no ClusterImageSets<br \/>\n2075416 &#8211; infraEnv failed to create image after restore<br \/>\n2075440 &#8211; The policyreport CR is created for spoke clusters until restarted the insights-client pod<br \/>\n2075739 &#8211; The lookup function won&#8217;t check the referred resource whether exist when using template policies<br \/>\n2076421 &#8211; Can&#8217;t select existing placement for policy or policyset when editing policy or policyset<br \/>\n2076494 &#8211; No policyreport CR for spoke clusters generated in the disconnected env<br \/>\n2076502 &#8211; The policyset card doesn&#8217;t show the cluster status(violation\/without violation) again after deleted one policy<br \/>\n2077144 &#8211; GRC Ansible automation wizard does not display error of missing dependent Ansible Automation Platform operator<br \/>\n2077149 &#8211; App UI shows no clusters cluster column of App Table when Discovery Applications is deployed to a managed cluster<br \/>\n2077291 &#8211; Prometheus doesn&#8217;t display acm_managed_cluster_info after upgrade from 2.4 to 2.5<br \/>\n2077304 &#8211; Create Cluster button is disabled only if other clusters exist<br \/>\n2077526 &#8211; ACM UI is very very slow after upgrade from 2.4 to 2.5<br \/>\n2077562 &#8211; Console\/App LC- Helm and Object bucket applications are not showing as deployed in the UI<br \/>\n2077751 &#8211; Can&#8217;t create a template policy from UI when the object&#8217;s name is referring Golang text template syntax in this policy<br \/>\n2077783 &#8211; Still show violation for clusterserviceversions after enforced &#8220;Detect Image vulnerabilities &#8221; policy template and the operator is installed<br \/>\n2077951 &#8211; Misleading message indicated that a placement of a policy became one managed only by policy set<br \/>\n2078164 &#8211; Failed to edit a policy without placement<br \/>\n2078167 &#8211; Placement binding and rule names are not created in yaml when editing a policy previously created with no placement<br \/>\n2078373 &#8211; Disable the hyperlink of *ks node in standalone MCE environment since the search component was not exists<br \/>\n2078617 &#8211; Azure public credential details get pre-populated with base domain name in UI<br \/>\n2078952 &#8211; View pod logs in search details returns error<br \/>\n2078973 &#8211; Crashed pod is marked with success in Topology<br \/>\n2079013 &#8211; Changing existing placement rules does not change YAML file<br \/>\n2079015 &#8211; Uninstall pod crashed when destroying Azure Gov cluster in ACM<br \/>\n2079421 &#8211; Hyphen(s) is deleted unexpectedly in UI when yaml is turned on<br \/>\n2079494 &#8211; Hitting Enter in yaml editor caused unexpected keys &#8220;key00x:&#8221; to be created<br \/>\n2079533 &#8211; Clusters with no default clusterset do not get assigned default cluster when upgrading from ACM 2.4 to 2.5<br \/>\n2079585 &#8211; When an Ansible Secret is propagated to an Ansible Application namespace, the propagated secret is shown in the Credentials page<br \/>\n2079611 &#8211; Edit appset placement in UI with a different existing placement causes the current associated placement being deleted<br \/>\n2079615 &#8211; Edit appset placement in UI with a new placement throws error upon submitting<br \/>\n2079658 &#8211; Cluster Count is Incorrect in Application UI<br \/>\n2079909 &#8211; Wrong message is displayed when GRC fails to connect to an ansible tower<br \/>\n2080172 &#8211; Still create policy automation successfully when the PolicyAutomation name exceed 63 characters<br \/>\n2080215 &#8211; Get a blank page after go to policies page in upgraded env when using an user with namespace-role-binding of default view role<br \/>\n2080279 &#8211; CVE-2022-29810 go-getter: writes SSH credentials into logfile, exposing sensitive credentials to local uses<br \/>\n2080503 &#8211; vSphere network name doesn&#8217;t allow entering spaces and doesn&#8217;t reflect YAML changes<br \/>\n2080567 &#8211; Number of cluster in violation in the table does not match other cluster numbers on the policy set details page<br \/>\n2080712 &#8211; Select an existing placement configuration does not work<br \/>\n2080776 &#8211; Unrecognized characters are displayed on policy and policy set yaml editors<br \/>\n2081792 &#8211; When deploying an application to a clusterpool claimed cluster after upgrade, the application does not get deployed to the cluster<br \/>\n2081810 &#8211; Type &#8216;-&#8216; character in Name field caused previously typed character backspaced in in the name field of policy wizard<br \/>\n2081829 &#8211; Application deployed on local cluster&#8217;s topology is crashing after upgrade<br \/>\n2081938 &#8211; The deleted policy still be shown on the policyset review page when edit this policy set<br \/>\n2082226 &#8211; Object Storage Topology includes residue of resources after Upgrade<br \/>\n2082409 &#8211; Policy set details panel remains even after the policy set has been deleted<br \/>\n2082449 &#8211; The hypershift-addon-agent deployment did not have imagePullSecrets<br \/>\n2083038 &#8211; Warning still refers to the `klusterlet-addon-appmgr` pod rather than the `application-manager` pod<br \/>\n2083160 &#8211; When editing a helm app with failing resources to another, the appsubstatus and the managedclusterview do not get updated<br \/>\n2083434 &#8211; The provider-credential-controller did not support the RHV credentials type<br \/>\n2083854 &#8211; When deploying an application with ansiblejobs multiple times with different namespaces, the topology shows all the ansiblejobs rather than just the one within the namespace<br \/>\n2083870 &#8211; When editing an existing application and refreshing the `Select an existing placement configuration`, multiple occurrences of the placementrule gets displayed<br \/>\n2084034 &#8211; The status message looks messy in the policy set card, suggest one kind status one a row<br \/>\n2084158 &#8211; Support provisioning bm cluster where no provisioning network provided<br \/>\n2084622 &#8211; Local Helm application shows cluster resources as `Not Deployed` in Topology [Upgrade]\n2085083 &#8211; Policies fail to copy to cluster namespace after ACM upgrade<br \/>\n2085237 &#8211; Resources referenced by a channel are not annotated with backup label<br \/>\n2085273 &#8211; Error querying for ansible job in app topology<br \/>\n2085281 &#8211; Template name error is reported but the template name was found in a different replicated policy<br \/>\n2086389 &#8211; The policy violations for hibernated cluster still be displayed on the policy set details page<br \/>\n2087515 &#8211; Validation thrown out in configuration for disconnect install while creating bm credential<br \/>\n2088158 &#8211; Object Storage Application deployed to all clusters is showing unemployed in topology [Upgrade]\n2088511 &#8211; Some cluster resources are not showing labels that are defined in the YAML<\/p>\n<p dir=\"ltr\">5. References:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/security\/cve\/CVE-2020-0404<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-4788<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-13974<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-19131<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-27820<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-0941<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3612<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3634<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3669<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3737<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3743<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3744<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3752<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3759<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3764<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3772<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3773<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-3918<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4002<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4037<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4083<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4157<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4189<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4197<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-4203<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-20322<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-21781<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-26401<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-29154<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-37159<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-41190<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-41864<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-42739<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-43056<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-43389<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-43565<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-43816<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-43858<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-43976<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-44733<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-45485<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-45486<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0001<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0002<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0235<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0286<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0322<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-0778<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-1011<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-21803<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-23806<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-24450<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-24778<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-24785<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-27191<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2022-29810<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#important<\/p>\n<p dir=\"ltr\">6. Contact:<\/p>\n<p dir=\"ltr\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p dir=\"ltr\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p dir=\"ltr\">iQIVAwUBYqGh9NzjgjWX9erEAQioMQ\/+N4V24GgHpDTRxKavLHSpma22mLya2Xgu<br \/>\n3zrYbLvVELbdqPyzke5T5cJ\/4ElXTr9s2Ev6KKoCXMmYKm3TKFnW9Y3J9XA7l7xk<br \/>\n8sWcAXzqWIgFdOXwzNOhKqn6PsHgZrbwH8UOYsThla+Qc1scK4LtTj67pEn0dqcv<br \/>\njl0PuRkgQb+tmdAbssXaKyrJeAPYk4B69iDwPoGdG5GJLkJybTs8KZrduZNnjMre<br \/>\nf5hRZHZU6AQlWv\/MH9m8Qh+F3O38Yu8I+sc71OGT7JVY4wcIuzCG2D21jdGcuQUh<br \/>\ngtnH5Ma17d2IqaJaX1KYGcdBu4F4bCKW581j8SBX2S7TGXhe9K1+If1ra47eIgeK<br \/>\n8DM\/qadQ52GhTK7Voh2EUvG0nQt2iOs6i6V3unCc9wCTZheJPsJHz3G\/9HKbWT54<br \/>\n4rsLjjdq\/9lMhU3eV4VzSxntCkXgISHmqFoEswCX6YmNeEDMeE6rPsO5+81ObA3n<br \/>\nbOXscXbYscj1FCfW5OboKpAtdtpQbajnS+46lUkW2y0jUyi5vRqWgx5mDQcbpiBj<br \/>\n0uGL7VSADIwKY\/i93itqYbVFyu7lsQI3FtQr+akOmaWm7MlDykbb81lyNByi6y86<br \/>\ng34x7lXyjuA+QW862w8v9NINUI7Csja0nnKHDe5XJdWO9cMHuyk6YrM9mv\/FpTb4<br \/>\nU39I87cKxqA=<br \/>\n=tOMt<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<br \/>\n&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Advanced Cluster Management 2.5 security updates, images, and bug fixes Advisory ID: RHSA-2022:4956-01 Product: Red Hat ACM Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:4956 Issue date: 2022-06-08 CVE Names: CVE-2020-0404 CVE-2020-4788 CVE-2020-13974 CVE-2020-19131 CVE-2020-27820 CVE-2021-0941 CVE-2021-3612 CVE-2021-3634 CVE-2021-3669 CVE-2021-3737 CVE-2021-3743 CVE-2021-3744 CVE-2021-3752 CVE-2021-3759 CVE-2021-3764 &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-25592","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/25592","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=25592"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/25592\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=25592"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=25592"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=25592"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}