Issued:
2024-02-26
Updated:
2024-02-26

RHSA-2024:0989 - Critical: Red Hat Multicluster GlobalHub 1.0.2 bug fixes and security updates


Synopsis

Critical: Red Hat Multicluster GlobalHub 1.0.2 bug fixes and security updates

Type/Severity

Security Advisory Critical

Topic

Red Hat Multicluster GlobalHub 1.0.2 General Availability release images, which fix bugs, provide security updates, and update container images.

Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section.

Description

Red Hat Multicluster GlobalHub 1.0.2 images

This advisory contains the container images for Red Hat Multicluster GlobalHub, which fix several bugs.

Security fix(es): CVE-2023-49568 go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

Solution

See the multicluster global hub product documentation for more information:

https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html-single/multicluster_global_hub/index

Affected Products

ProductVersionArch
Multicluster Global Hub1.0x86_64

Fixes

CVEs

References


Additional information