RHSA-2022:1083: Moderate: Red Hat Advanced Cluster Management 2.3.8 security and container updates
Red Hat Advanced Cluster Management for Kubernetes 2.3.8 images<br>Red Hat Advanced Cluster Management for Kubernetes provides the<br>capabilities to address common challenges that administrators and site<br>reliability engineers face as they work across a range of public and<br>private cloud environments. Clusters and applications are all visible and<br>managed from a single console—with security policy built in.<br>This advisory contains the container images for Red Hat Advanced Cluster<br>Management for Kubernetes, which fix several bugs. See the following<br>Release Notes documentation, which will be updated shortly for this<br>release, for additional details about this release:<br><a href="https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.3/html/releasenotes/" target="blank">https://access.redhat.com/documentation/en-us/redhatadvancedclustermanagementforkubernetes/2.3/html/releasenotes/</a> Security updates:<br><li> nanoid: Information disclosure via valueOf() function (CVE-2021-23566)</li> <li> nodejs-shelljs: improper privilege management (CVE-2022-0144)</li> <li> follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor (CVE-2022-0155)</li> <li> node-fetch: exposure of sensitive information to an unauthorized actor (CVE-2022-0235)</li> <li> follow-redirects: Exposure of Sensitive Information via Authorization Header leak (CVE-2022-0536)</li> Bug fix:<br><li> RHACM 2.3.8 images (Bugzilla #2062316)</li>
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:1083?
The severity of RHSA-2022:1083 is classified as important.
What are the main vulnerabilities addressed in RHSA-2022:1083?
RHSA-2022:1083 addresses security vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes version 2.3.8.
How do I fix RHSA-2022:1083?
To fix RHSA-2022:1083, update your Red Hat Advanced Cluster Management for Kubernetes to the latest patched version.
Which versions are affected by RHSA-2022:1083?
RHSA-2022:1083 affects Red Hat Advanced Cluster Management for Kubernetes versions prior to 2.3.8.
Is a reboot required after applying the fix for RHSA-2022:1083?
A reboot is not required after applying the fix for RHSA-2022:1083.