RHSA-2021:2437MediumCVSS 8.6

Red Hat Security Advisory: OpenShift Container Platform 4.8.2 packages and security update

Published
July 27, 2021
Last Modified
August 15, 2026

🔗 CVE IDs covered (26)

📋 Description

CVE-2021-3114 — golang: crypto/elliptic: incorrect operations on the P-224 curve CVE-2021-3121 — gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation CVE-2021-3636 — openshift: Injected service-ca.crt incorrectly contains additional internal CAs CVE-2021-20291 — containers/storage: DoS via malicious image CVE-2021-21419 — python-eventlet: improper handling of highly compressed data and memory allocation with excessive size allows DoS CVE-2021-21602 — jenkins: Arbitrary file read vulnerability in workspace browsers CVE-2021-21603 — jenkins: XSS vulnerability in notification bar CVE-2021-21604 — jenkins: Improper handling of REST API XML deserialization errors CVE-2021-21605 — jenkins: Path traversal vulnerability in agent names CVE-2021-21606 — jenkins: Arbitrary file existence check in file fingerprints CVE-2021-21607 — jenkins: Excessive memory allocation in graph URLs leads to denial of service CVE-2021-21608 — jenkins: Stored XSS vulnerability in button labels CVE-2021-21609 — jenkins: Missing permission check for paths with specific prefix CVE-2021-21610 — jenkins: Reflected XSS vulnerability in markup formatter preview CVE-2021-21611 — jenkins: Stored XSS vulnerability on new item page CVE-2021-21623 — jenkins-2-plugins/matrix-auth: Incorrect permission checks in Matrix Authorization Strategy Plugin CVE-2021-21639 — jenkins: lack of type validation in agent related REST API CVE-2021-21640 — jenkins: view name validation bypass CVE-2021-21642 — jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. CVE-2021-21643 — jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. CVE-2021-21644 — jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability. CVE-2021-21645 — jenkins-2-plugins/config-file-provider: Does not perform permission checks in several HTTP endpoints. CVE-2021-21648 — jenkins-2-plugins/credentials: Reflected XSS vulnerability in Credentials Plugin CVE-2021-25735 — kubernetes: Validating Admission Webhook does not observe some previous fields CVE-2021-25737 — kubernetes: Holes in EndpointSlice Validation Enable Host Network Hijack CVE-2021-30465 — runc: vulnerable to symlink exchange attack

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.8
  • afterburn-0:5.0.0-1.rhaos4.8.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • afterburn-0:5.0.0-1.rhaos4.8.el8.s390x as a component of Red Hat OpenShift Container Platform 4.8
  • afterburn-0:5.0.0-1.rhaos4.8.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.8
  • afterburn-debuginfo-0:5.0.0-1.rhaos4.8.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • afterburn-debuginfo-0:5.0.0-1.rhaos4.8.el8.s390x as a component of Red Hat OpenShift Container Platform 4.8
  • afterburn-debuginfo-0:5.0.0-1.rhaos4.8.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.8
  • atomic-openshift-service-idler-0:4.8.0-202106281541.p0.git.39cfc66.assembly.stream.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • atomic-openshift-service-idler-0:4.8.0-202106281541.p0.git.39cfc66.assembly.stream.el8.s390x as a component of Red Hat OpenShift Container Platform 4.8
  • atomic-openshift-service-idler-0:4.8.0-202106281541.p0.git.39cfc66.assembly.stream.el8.src as a component of Red Hat OpenShift Container Platform 4.8
  • atomic-openshift-service-idler-0:4.8.0-202106281541.p0.git.39cfc66.assembly.stream.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.8
  • butane-0:0.12.1-1.rhaos4.8.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • butane-0:0.12.1-1.rhaos4.8.el8.s390x as a component of Red Hat OpenShift Container Platform 4.8
  • butane-0:0.12.1-1.rhaos4.8.el8.src as a component of Red Hat OpenShift Container Platform 4.8
  • butane-0:0.12.1-1.rhaos4.8.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.8
  • butane-debuginfo-0:0.12.1-1.rhaos4.8.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • butane-debuginfo-0:0.12.1-1.rhaos4.8.el8.s390x as a component of Red Hat OpenShift Container Platform 4.8
  • butane-debuginfo-0:0.12.1-1.rhaos4.8.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.8
  • console-login-helper-messages-0:0.20.3-1.rhaos4.8.el8.noarch as a component of Red Hat OpenShift Container Platform 4.8
  • console-login-helper-messages-0:0.20.3-1.rhaos4.8.el8.src as a component of Red Hat OpenShift Container Platform 4.8
  • console-login-helper-messages-issuegen-0:0.20.3-1.rhaos4.8.el8.noarch as a component of Red Hat OpenShift Container Platform 4.8
  • console-login-helper-messages-profile-0:0.20.3-1.rhaos4.8.el8.noarch as a component of Red Hat OpenShift Container Platform 4.8
  • coreos-installer-0:0.9.0-6.rhaos4.8.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • coreos-installer-0:0.9.0-6.rhaos4.8.el8.s390x as a component of Red Hat OpenShift Container Platform 4.8
  • coreos-installer-0:0.9.0-6.rhaos4.8.el8.src as a component of Red Hat OpenShift Container Platform 4.8
  • coreos-installer-0:0.9.0-6.rhaos4.8.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.8
  • coreos-installer-bootinfra-0:0.9.0-6.rhaos4.8.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • coreos-installer-bootinfra-0:0.9.0-6.rhaos4.8.el8.s390x as a component of Red Hat OpenShift Container Platform 4.8
  • coreos-installer-bootinfra-debuginfo-0:0.9.0-6.rhaos4.8.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • coreos-installer-bootinfra-debuginfo-0:0.9.0-6.rhaos4.8.el8.s390x as a component of Red Hat OpenShift Container Platform 4.8
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.8 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.8/updating/updating-cluster-cli.html Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible. Workaround: * Prevent untrusted users from creating or modifying EndpointSlices * Creating a validating admission webhook that prevents EndpointSlices with endpoint addresses in the 127.0.0.0/8 and 169.254.0.0/16 ranges Workaround: The impact of the vulnerability is reduced if SELinux is in enforcing mode using the container-selinux policy. The container-selinux policy is installed and enabled by default on RHEL 7 and 8, as well as OpenShift Container Platform 3.x and 4.x. Customers running affected versions of RHEL are strongly recommended to apply RPM updates from the RHEL 8 channel and RHEL 7 Extras channel as soon as errata becomes available. Customers running affected versions of OpenShift Container Platform are strongly recommended to upgrade as soon as errata becomes available. Customers of OpenShift Online or OpenShift Dedicated have SELinux enabled in enforcing mode in every host across all clusters. Therefore, It is expected that OSO/OSD both have a reduced impact from this issue, with security patches made available during upcoming maintenance windows.

🔗 References (13)