The vendor explicitly identifies these products or versions as containing the fix.
- registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:34651d8005c0407444a36f6c30d6a2eaff0e6de9343e50eceabb1ba6e3e71d71_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:7130706447b1530f9bfde9d8ce3f44144b7ce2936a76c3b536838ec7a9151010_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:9981b3d7cf1ce5bca251044e1e4bdc7aa0c36187d3afcff3090f77338b2d42a1_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:fdcd78a10d394fa844c443f77192fc70038c74c9ad6c0855fdbe1791c4e24cb1_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.11
- registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:001e8b921bdc6229be7b954c79609921545e7227f0588620fa5119c0c092b75c_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:7ec13a6f2b21f85d284d14783ace3ceded93f322577d7c0e1dc0384e42c7a844_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:b677c50b011d9ad2551e2bf00ec67a22a78e465f8cfccdfd001527e97ffc2a77_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:dd16c51dae5d2efd3ff2e29f81e3b7ae3f3f28a17e684ae888a83f5469307b06_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.13
- registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:4341ce0bc756c33bb1035dd63f907b9f60557d97ff8a76d53842b668845a6e84_amd64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:9246d7ed264daf4cb915224d27acd5cc4c11c64dab119cdd9830bcc7bdaedbc1_arm64 as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:9e45059a2c2b1ced8c089294a8191021472ab93bb726033c18fe5a0a4caa5a6d_ppc64le as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- registry.redhat.io/rhacm2/multicluster-operators-subscription-rhel9@sha256:afaeae9b62e211ffbafc0c271c313bf5119f62d2b8f8c8ba515e4de075011e22_s390x as a component of Red Hat Advanced Cluster Management for Kubernetes 2.14
- Summary
- A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables the tenant to deploy arbitrary cluster-scoped resources, leading to privilege escalation and potential arbitrary code execution across the cluster.
- Remediation
- Before you apply this update, make sure all previously released errata that are relevant to your system are applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
