Red Hat Alert
2889Warning Date
Severity Level
Warning Number
Target Sector
13 September, 2022
● Critical
2022-5230
All
Red Hat has released security updates to address several vulnerabilities in the following products:
- OpenShift Container Platform 4.9.48
- Red Hat OpenShift Container Platform for IBM Z and LinuxONE
- Red Hat OpenShift Container Platform
- Red Hat OpenShift Container Platform for ARM 64
- Red Hat OpenShift Container Platform for Power
- Multicluster Engine for Kubernetes 2.0.2
- multicluster engine for Kubernetes
- Multicluster Engine for Kubernetes 2.1.1
- multicluster engine for Kubernetes
- Red Hat Advanced Cluster Management 2.6.1
- Red Hat Advanced Cluster Management for Kubernetes
- Migration Toolkit for Containers (MTC) 1.7.4
- Red Hat Migration Toolkit
An attacker could exploit these vulnerabilities by doing the following:
- Denial of service attack (DoS)
- Command injection
- Authentication bypass
- Sandbox Escape
- Sensitive information disclosure
The CERT team encourages users to review Red Hat security advisory and apply the necessary updates: