The vendor explicitly identifies these products or versions as containing the fix.
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:0ace6b11b0f86b0aaf75c0b07d505bf07757d73d2b720c1375c7f1bd43c2adf0_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:404869ee47585fee60db24267b6ec8da18d78db3353b429f63c1a5d5b2435909_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:af6caffd0b04b77f6eb5b1770ecf5ac3d5461cccccc45c8ed4bd461896fe5a30_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:b781f7db2db26c754d9be9a7627ff846f45eb48210906e17c8061a9a0fb034eb_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.17
- Summary
- A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an `Upgrade: websocket` header. An unauthenticated attacker can exploit this by sending a specially crafted HTTP POST request to the `/federated` endpoint with the `Upgrade: websocket` header. This allows the attacker to bypass authentication and access federated search results across all configured remote managed hubs, leading to information disclosure.
- Remediation
- Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
