RHSA-2020:0933MediumCVSS 6.5

Red Hat Security Advisory: OpenShift Container Platform 4.3.9 ose-openshift-apiserver-container security update

Published
April 1, 2020
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2019-11254 — kubernetes: Denial of service in API server via crafted YAML payloads by authorized users CVE-2020-8552 — kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion

🎯 Affected products2

  • Red Hat OpenShift Container Platform 4.3
  • openshift4/ose-openshift-apiserver-rhel7@sha256:1bebc10fd956168ec31e45ce2d3753f215b59a533c834d41c6f83eca4db2da84_amd64 as a component of Red Hat OpenShift Container Platform 4.3

✅ Remediation

For OpenShift Container Platform 4.3 see the following documentation, which will be updated shortly for release 4.3.9, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.3/updating/updating-cluster-cli.html. Workaround: Prevent unauthenticated or unauthorized access to the API server Workaround: Prevent unauthenticated or unauthorized access to all APIs

🔗 References (4)