RHSA-2020:3578MediumCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.5.8 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2020-7015 — kibana: XSS in TSVB visualization (ESA-2020-08) CVE-2020-14040 — golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash
🎯 Affected products13
- Red Hat OpenShift Container Platform 4.5
- openshift4/ose-cluster-network-operator@sha256:084fd8364f530a54b7f8beba9d562a7f0bd8fed2dfe34f1d4cb35b1f32b6b30c_ppc64le as a component of Red Hat OpenShift Container Platform 4.5
- openshift4/ose-cluster-network-operator@sha256:132c0a4112e13fae6abed900fd1d7c14d21b443bb39c21c67fa0223d323dc3f5_amd64 as a component of Red Hat OpenShift Container Platform 4.5
- openshift4/ose-cluster-network-operator@sha256:9ec5a9ae1f08f0bc6fa1eb4516b5f64e7e89f3ef49589854f68ecc362b6c8cac_s390x as a component of Red Hat OpenShift Container Platform 4.5
- openshift4/ose-cluster-version-operator@sha256:2692648061909c425f2133e958002a0ab8e2d2a89c5272e8c516651a4ae4e955_amd64 as a component of Red Hat OpenShift Container Platform 4.5
- openshift4/ose-cluster-version-operator@sha256:d852f36c75d997fb5ed8f4f6c1f7eeaaad492c62fd39dd33af73e00194fedf45_ppc64le as a component of Red Hat OpenShift Container Platform 4.5
- openshift4/ose-cluster-version-operator@sha256:ff5be8762429be98d424da42033a3cdc941ba969e0a6a9ec1027666c33538cfa_s390x as a component of Red Hat OpenShift Container Platform 4.5
- openshift4/ose-elasticsearch-operator@sha256:7299422adec799d34c931a3e61fa7c64b830d0b63ca8071a2080ce408e74e271_ppc64le as a component of Red Hat OpenShift Container Platform 4.5
- openshift4/ose-elasticsearch-operator@sha256:7bb27b815f70cbc4e39741425e643bdb7bd0781bc3fec98eee1be78e5765804e_s390x as a component of Red Hat OpenShift Container Platform 4.5
- openshift4/ose-elasticsearch-operator@sha256:b6199dad19e9c05af81d4652d3927c263ec1e8853726632b703dbc9ee4cddfa4_amd64 as a component of Red Hat OpenShift Container Platform 4.5
- openshift4/ose-logging-kibana6@sha256:0fd0bdf8433265a5da7b3d9f61cb5896d649c3e2966c77f79f02023ef0a43d20_amd64 as a component of Red Hat OpenShift Container Platform 4.5
- openshift4/ose-logging-kibana6@sha256:651ec08a2be0652c9d7b709931876c2910a3c0b1881bdf75317fcaaa34af11e4_ppc64le as a component of Red Hat OpenShift Container Platform 4.5
- openshift4/ose-logging-kibana6@sha256:e22e477267031f697463351872ba50f86dce172d600fb208f91c44e1e136e397_s390x as a component of Red Hat OpenShift Container Platform 4.5
✅ Remediation
For OpenShift Container Platform 4.5 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.5/release_notes/ocp-4-5-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.5/updating/updating-cluster-cli.html. Workaround: To mitigate this vulnerability you can set "metrics.enabled: false" in kibana.yml
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2020:3578
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1849037
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1853652
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3578.json