The vendor explicitly identifies these products or versions as containing the fix.
- registry.redhat.io/rhacm2/insights-client-rhel9@sha256:537de767f601dcf50bda77f5dd30db30b4c80f5b8f96e14646c2cd5ac0dff40a_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/insights-client-rhel9@sha256:606e1b82a1b2af84477860b1f30de6153741a322d5fb3e52ef613ff141ae4ce5_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/insights-client-rhel9@sha256:6992f5fa3c450250c72b093f9514cacee23617bef892b2e71e8ec00a408c39d0_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/insights-client-rhel9@sha256:945d48295ae375358fcd9e6a808b8862c4c6e215681cd56c3d0ff10401c4aff8_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/insights-client-rhel9@sha256:181780b5f0e725e081544a15c2eb5d7db4b4549086e8821ca8b93b4f591028ed_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/insights-client-rhel9@sha256:464b4b109bd3ec70e6494ba620593f3e7ce122812dc1afe82c3e5f4022313ec0_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/insights-client-rhel9@sha256:d8a148175b7571488284dc8195118d300906dda3f687eedc19dc2f35f550d39e_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/insights-client-rhel9@sha256:e6b93f3275cdd47ec83fc13900d93628da562b5077a1881fae7319059da046b2_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/insights-client-rhel9@sha256:3b44bbca3e5d4b9f4e7a71735b9da48d5c985a2478a04e1f7f42753a0b2c76f5_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/insights-client-rhel9@sha256:819a522380075db1997770fca7c1f1a3b6fbfbd044761d80c876abb735652035_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/insights-client-rhel9@sha256:86840f16a20d13870471cd2e8a2a3ea49f77cb5fad58768fced51cc4e6786280_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- registry.redhat.io/rhacm2/insights-client-rhel9@sha256:cbdadc6f8a26e231a5789a38aa90aaf190744b0b63c8b8305bed70427a9a005f_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.15
- Summary
- A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability allows a malicious spoke to redirect authenticated requests to unintended API endpoints, potentially leading to information disclosure or unauthorized access.
- Remediation
- Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
