Red Hat Security Advisory: OpenShift Container Platform 4.3.38 jenkins and openshift security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2019-17638 — jetty: double release of resource can lead to information disclosure CVE-2020-2220 — jenkins: Stored XSS vulnerability in job build time trend CVE-2020-2221 — jenkins: Stored XSS vulnerability in upstream cause CVE-2020-2222 — jenkins: Stored XSS vulnerability in 'keep forever' badge icons CVE-2020-2223 — jenkins: Stored XSS vulnerability in console links CVE-2020-2229 — jenkins: user-specified tooltip values leads to stored cross-site scripting CVE-2020-2230 — jenkins: stored XSS vulnerability in project naming strategy CVE-2020-2231 — jenkins: stored XSS vulnerability in 'trigger builds remotely' CVE-2020-8557 — kubernetes: Node disk DOS by writing to container /etc/hosts
🎯 Affected products7
- Red Hat OpenShift Container Platform 4.3
- jenkins-0:2.235.5.1600415514-1.el7.noarch as a component of Red Hat OpenShift Container Platform 4.3
- jenkins-0:2.235.5.1600415514-1.el7.src as a component of Red Hat OpenShift Container Platform 4.3
- openshift-0:4.3.37-202009120213.p0.git.0.dffefe4.el8.src as a component of Red Hat OpenShift Container Platform 4.3
- openshift-hyperkube-0:4.3.37-202009120213.p0.git.0.dffefe4.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.3
- openshift-hyperkube-0:4.3.37-202009120213.p0.git.0.dffefe4.el8.s390x as a component of Red Hat OpenShift Container Platform 4.3
- openshift-hyperkube-0:4.3.37-202009120213.p0.git.0.dffefe4.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.3
✅ Remediation
For OpenShift Container Platform 4.3 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.3/release_notes/ocp-4-3-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.3/updating/updating-cluster-cli.html. Workaround: On OpenShift Container Platform (OCP) 3.11 and 4.x it's possible to set the allowPrivilegeEscalation Security Context Constraint to 'false' to prevent this. Note that this is set to 'true' by default, and setting it to false will prevent certain binaries which require setuid to stop working. On OCP 3.11 for example the 'ping' command will no longer work [1]. On OCP 4.x and later the 'ping' command will work with allowPrivilegeEscalation set to False, but other setuid binaries will not work. [1] https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2020:3808
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1835977
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857425
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857427
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857431
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1857433
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_3808.json