The vendor explicitly identifies these products or versions as containing the fix.
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:44ddf9fae94ac2f4e74c35433a612c8a0dabf531384f2974a8c4872cde0efaa1_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:5291e93f95e8350e361470eec8cd6cac6e697aa712fb061bfa780981a47cb17b_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:a1af35a23b6ed7aeb297bb59d6ffa84505769c36727c6628667dddd4d87569ad_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:e934fad530ced942202a8e893c1ee4a931856709a46a9d711e67779cbf9d48ee_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:016023aaab9f3476900a3e7bf2126875500dd171834bad8c395f42a2baae795e_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:4641f23fc762a798ea7a94e85c44fbf21f37fb8c74d93d9f39c4fe120fd8704a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:dd29bb691d5495ef504883b012248b03a4d8109000ba85dc470b0acb280aab40_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:f04d7d5454141691568e02f461bdca9bc58cc07f33244caf4f1caf27cd1d5866_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:04fe2d4880d42890325ff697c84bd413218a9fd7f316c4dd195eb307ee2ae859_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:3ffb54a51d08d77a3340914bac096cb31dc71145f681a9bcd311f1c38e4256a1_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:b1b9c8a2641af71bc376784ad4ee622e116529a512e1a619a227fc8a19bd0af2_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/cluster-backup-rhel9-operator@sha256:ffa6981a04f2439051744797f933da5221f7a96c46998188014e90b999a3ffd3_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- Summary
- A flaw was found in cluster-backup-operator. A namespace administrator in open-cluster-management-backup can create a Restore Custom Resource (CR) with malicious hooks. These hooks allow the execution of arbitrary commands within any matching restored pod, leading to the exfiltration of ServiceAccount tokens. This bypasses normal access controls, granting the attacker unauthorized execution access to pods and their associated Service Accounts.
- Remediation
- Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
