- Issued:
- 2025-01-21
- Updated:
- 2025-01-21
RHSA-2025:0560 - Important: Red Hat Multicluster GlobalHub 1.2.1 bug fixes and container updates
Synopsis
Important: Red Hat Multicluster GlobalHub 1.2.1 bug fixes and container updates
Type/Severity
Security Advisory Important
Topic
Red Hat multicluster global hub 1.2.1 general availability and release images provide enhancements, security fixes, and updated container images.
Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section.
Description
Red Hat multicluster global hub 1.2.1 images
This advisory contains the container images for multicluster global hub. These container images provide enhancements.
This advisory contains enhancements and updates to the global hub container images.
Security fix(es):
- golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (CVE-2024-45337)
- golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)
Solution
Before applying this update, make sure all previously released erratas are relevant and have been applied to your system.
See the multicluster global hub product documentation for more information:
Affected Products
| Product | Version | Arch |
|---|---|---|
| Multicluster Global Hub | 1.2 | x86_64 |
Fixes
CVEs
- CVE-2019-12900
- CVE-2021-43618
- CVE-2022-48554
- CVE-2023-7104
- CVE-2023-22745
- CVE-2023-29491
- CVE-2023-37920
- CVE-2024-2398
- CVE-2024-3596
- CVE-2024-3651
- CVE-2024-6119
- CVE-2024-6232
- CVE-2024-6345
- CVE-2024-10963
- CVE-2024-25062
- CVE-2024-28182
- CVE-2024-28834
- CVE-2024-28835
- CVE-2024-34397
- CVE-2024-37891
- CVE-2024-45337
- CVE-2024-45338
- CVE-2024-50602
References
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.