The vendor explicitly identifies these products or versions as containing the fix.
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:44ddf9fae94ac2f4e74c35433a612c8a0dabf531384f2974a8c4872cde0efaa1_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:5291e93f95e8350e361470eec8cd6cac6e697aa712fb061bfa780981a47cb17b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:a1af35a23b6ed7aeb297bb59d6ffa84505769c36727c6628667dddd4d87569ad_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:e934fad530ced942202a8e893c1ee4a931856709a46a9d711e67779cbf9d48ee_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:016023aaab9f3476900a3e7bf2126875500dd171834bad8c395f42a2baae795e_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:4641f23fc762a798ea7a94e85c44fbf21f37fb8c74d93d9f39c4fe120fd8704a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:dd29bb691d5495ef504883b012248b03a4d8109000ba85dc470b0acb280aab40_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:f04d7d5454141691568e02f461bdca9bc58cc07f33244caf4f1caf27cd1d5866_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:04fe2d4880d42890325ff697c84bd413218a9fd7f316c4dd195eb307ee2ae859_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:3ffb54a51d08d77a3340914bac096cb31dc71145f681a9bcd311f1c38e4256a1_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:b1b9c8a2641af71bc376784ad4ee622e116529a512e1a619a227fc8a19bd0af2_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:ffa6981a04f2439051744797f933da5221f7a96c46998188014e90b999a3ffd3_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- Summary
- A flaw was found in the cluster-backup-operator. An attacker with write access to the backup storage location or the ability to create a Velero Backup object can inject malicious Role-Based Access Control (RBAC) resources into a backup. When this tampered backup is restored, the operator processes the malicious content, leading to a privilege escalation from backup-namespace-admin to hub cluster-admin. This allows the attacker to gain administrative control over the entire cluster.
- Remediation
- Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
