SB2024040357 - Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.3



SB2024040357 - Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.3

Published: April 3, 2024

Security Bulletin ID SB2024040357
Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Path traversal (CVE-ID: CVE-2023-49569)

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can overwrite arbitrary files on the system. Applications are only affected if they are using the ChrootOS, which is the default when using "Plain" versions of Open and Clone funcs (e.g. PlainClone).


2) Use of uninitialized variable (CVE-ID: CVE-2024-26147)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to usage of an uninitialized variable when using the LoadIndexFile or DownloadIndexFile functions in the repo package or the LoadDir function in the plugin package. If index.yaml file or a plugins plugin.yaml file are missing in the repository, the application crashes.


3) Information disclosure (CVE-ID: CVE-2019-25210)

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application, which displays values of secrets when the --dry-run flag is used. A remote attacker can gain access to sensitive information.


Remediation

Install update from vendor's website.