RHSA-2019:2817MediumCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 3.11 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2019-9512 — HTTP/2: flood using PING frames results in unbounded memory growth CVE-2019-9514 — HTTP/2: flood using HEADERS frames results in unbounded memory growth CVE-2019-10214 — containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure
🎯 Affected products6
- Red Hat OpenShift Container Platform 3.11
- cri-o-0:1.11.16-0.2.dev.rhaos3.11.git3f89eba.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- cri-o-0:1.11.16-0.2.dev.rhaos3.11.git3f89eba.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- cri-o-0:1.11.16-0.2.dev.rhaos3.11.git3f89eba.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- cri-o-debuginfo-0:1.11.16-0.2.dev.rhaos3.11.git3f89eba.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- cri-o-debuginfo-0:1.11.16-0.2.dev.rhaos3.11.git3f89eba.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
✅ Remediation
See the following documentation, which will be updated shortly for release 3.11.146, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html