The vendor explicitly identifies these products or versions as containing the fix.
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:2e503ccacdbdb7247763d516e2f53e1ca4b31c4094a36b253b3cf3153dcf8184_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:8d7946dad68234eb3f93f271eb37e22034eaf083b481e4a3e613fb52d3202bf7_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:cf859d871fd4ecbc6a5e6f49d26eeb8a11e4d7ea7081c0064465b55c52002894_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:deba8c8022a0681937918046e932d980cffbbc33dab6a8b009743aed830a36bf_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:200e4551c2fbb3f5b292bcdbc0e39d16740842ead63a99632591da7cf9cb462e_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:7bdb8b3c70a05d65da793182c392bd81c6278cb79543aa3e191b3888ddad2a2d_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:baee0733dd1141f90342b0dd02136ca27f590cd0c27214f61f8815b0a90ed665_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:defa1de983ad0d1e6ad8cfd3c8cee1f73508760254ee00d57a4d175ac583c5fc_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:0e053b448d320b4cfedf182323a1beb2423b512fe98a2edb1383488d4ec40fcd_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:2b43c8877d2df09941dd67f1ed9aad3559be2e39231262cebad3496c700e29ea_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:379a5067be0f1a23fea5a4145422c1c72ab6d8b4c493a89c7463e62fce054ca8_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/acm-search-v2-api-rhel9@sha256:789be35c268017dceb3a57c2868b17331b4e26e28f82bd02d31691d3259c5b31_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- Summary
- A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This can lead to memory exhaustion of the search-api pod, resulting in a Denial of Service (DoS).
- Remediation
- Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
