RHSA-2019:2594HighCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.1.14 security and bug fix update
🔗 CVE IDs covered (2)
📋 Description
CVE-2019-9512 — HTTP/2: flood using PING frames results in unbounded memory growth CVE-2019-9514 — HTTP/2: flood using HEADERS frames results in unbounded memory growth
🎯 Affected products95
- Red Hat OpenShift Container Platform 4.1
- openshift4/apb-base@sha256:183441575a8a0ba144fdd346e5ab560a067725a9b66d890493c326e14135512e_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/mariadb-apb@sha256:a446829513325ac146b2aa1b555347b57a2377712df6cd8a431c1dbec0614331_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/mediawiki-apb@sha256:0a1ab047c6a93e3531f20673b275854361f36e2ebd4894b5ad1705c3dde42a76_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/mediawiki@sha256:8014f0d73799f7f26b56a3d908b55de3103103f57a507d48fe9830c7d605f85d_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/mysql-apb@sha256:5772d2a584b96249c535df55b501ffe891162d7651b18244cdc16ab2f0d563dc_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-ansible-operator@sha256:9469e5ed49937aeb64f0a3dbb5332f087c8498494127a5c507c02c3d4286afb1_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-aws-machine-controllers@sha256:e5f585aa452461ee95d55e84d81be54a82a458a54dbcad1f68a8f28edeb7638b_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-azure-machine-controllers@sha256:9f3199e5226fdcd5abe34a6f2e3a6ad7e7ad3f59edbff2bfd9b4c84566897eae_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-baremetal-machine-controllers@sha256:d9ca5e81aa2fb401f9c5bfb63e85fc5d93ae1e657ab992e879a2b9d520f3fea3_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cli-artifacts@sha256:bacaec21f6101ef686bb07b5d6e80b0b3ad06ab9a4d4f6e611ca3103c0030d7e_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cli@sha256:bb846647aa233adddf5ed39056fdf98a7d9dc3abef4c985df3de698a44ecc7fd_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cloud-credential-operator@sha256:27c7bac07c2a2a38ddb65a9997b22946fbe37ddd06ecf52eccd0ef9235ae47ba_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-authentication-operator@sha256:67dc9d9d90e5b37c73eda524a13e0bd98834b225adbfccc9d6c09a35a130c8f4_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-autoscaler-operator@sha256:989948cb9998b518f3c325a2af3b24cfb7033ad2ac8be96cb3fafce2b4077435_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-autoscaler@sha256:b995c30d43493a8d393282c760584605951048dbe395eeac6b6b1bec269ff3ad_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-bootstrap@sha256:9a676b7e363f022a511ab07ae81242b5c6d03523db11c37b0bf47e0f0324c9d8_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-capacity@sha256:24db95a9d24960c14775136419eed7dfddb7b7d70577fab77a63b64fc66d53a7_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-config-operator@sha256:3b210b7313b4853f777d19248ba746b3d29251a3409124f984ae212809930427_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-dns-operator@sha256:5f70ba7ebcee1ecb9f65c8b43280935866607fc3dee6329ed473169f2acebe05_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-image-registry-operator@sha256:5c8fa5eb3828277f31ca0d4f7aedfee8e66dc0cfa3542772e6ac13c6b131644d_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-ingress-operator@sha256:b33e32eaac7d15947e32cbeb9d45e9ae3e6fbe470611ab78f28cfc99d8759b68_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-kube-apiserver-operator@sha256:af88e84a2957ba9eeb1e5e3cdf9cf559ccb0de08d7a16c58a19c8eb805ba5a39_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-kube-controller-manager-operator@sha256:ca1e29c0c4eb029ed4d5544d5fde000000aa007f1d8e0fcf0fc0d317b5e06784_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-kube-scheduler-operator@sha256:6f30eebebe4b774acd19eadeae80c4a7c8ccb503389c354bc76fc0f778cefe2b_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-logging-operator@sha256:7926e2be0854ff3edac0ced6950a0be04ad26d46a5da638611457c3fe0f1a19a_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-machine-approver@sha256:3535b9ccd701ac3fa6b6a8339f6c10d6e74dd4d8f5f810690fa7e272ee82f837_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-monitoring-operator@sha256:05d69056c09c34d095ccedc757ecf2692690c72d2bee4e6b6afc58b01ec55d9c_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-network-operator@sha256:2561079cceff11035c216fea71c0a10622696266aa5a9323ef13806c91537a68_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- openshift4/ose-cluster-node-tuning-operator@sha256:b6fa66947d674eb2fc12b38fb9355c43c57a484d85e56dd013960a760046b793_amd64 as a component of Red Hat OpenShift Container Platform 4.1
- +65 more not shown
✅ Remediation
For OpenShift Container Platform 4.1 see the following documentation, which will be updated shortly for release 4.1.14, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.1/release_notes/ocp-4-1-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.1/updating/updating-cluster-cli.html.
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2019:2594
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1717794
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1729510
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735363
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1735744
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1737156
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1737164
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1737386
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1740044
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1741067
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1741499
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1741694
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1743119
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1743259
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1743418
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1743587
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1743748
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1743771
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_2594.json