RHSA-2021:2438MediumCVSS 8.6

Red Hat Security Advisory: OpenShift Container Platform 4.8.2 bug fix and security update

Published
July 27, 2021
Last Modified
August 15, 2026

🔗 CVE IDs covered (28)

📋 Description

CVE-2016-2183 — SSL/TLS: Birthday attack against 64-bit block ciphers (SWEET32) CVE-2020-7774 — nodejs-y18n: prototype pollution vulnerability CVE-2020-15106 — etcd: Large slice causes panic in decodeRecord method CVE-2020-15112 — etcd: DoS in wal/wal.go CVE-2020-15113 — etcd: directories created via os.MkdirAll are not checked for permissions CVE-2020-15114 — etcd: gateway can include itself as an endpoint resulting in resource exhaustion and leads to DoS CVE-2020-15136 — etcd: no authentication is performed against endpoints provided in the --endpoints flag CVE-2020-26160 — jwt-go: access restriction bypass vulnerability CVE-2020-28469 — nodejs-glob-parent: Regular expression denial of service CVE-2020-28500 — nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions CVE-2020-28852 — golang.org/x/text: Panic in language.ParseAcceptLanguage while processing bcp47 tag CVE-2021-3114 — golang: crypto/elliptic: incorrect operations on the P-224 curve CVE-2021-3121 — gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation CVE-2021-20206 — containernetworking-cni: Arbitrary path injection via type field in CNI configuration CVE-2021-20218 — fabric8-kubernetes-client: vulnerable to a path traversal leading to integrity and availability compromise CVE-2021-20291 — containers/storage: DoS via malicious image CVE-2021-22133 — go.elastic.co/apm: leaks sensitive HTTP headers during panic CVE-2021-23337 — nodejs-lodash: command injection via template CVE-2021-23362 — nodejs-hosted-git-info: Regular Expression denial of service via shortcutMatch in fromUrl() CVE-2021-23368 — nodejs-postcss: Regular expression denial of service during source map parsing CVE-2021-23382 — nodejs-postcss: ReDoS via getAnnotationURL() and loadAnnotation() in lib/previous-map.js CVE-2021-26539 — sanitize-html: improper handling of internationalized domain name (IDN) can lead to bypass hostname whitelist validation CVE-2021-26540 — sanitize-html: improper validation of hostnames set by the "allowedIframeHostnames" option can lead to bypass hostname whitelist for iframe element CVE-2021-27292 — nodejs-ua-parser-js: ReDoS via malicious User-Agent header CVE-2021-28092 — nodejs-is-svg: ReDoS via malicious string CVE-2021-29059 — nodejs-is-svg: Regular expression denial of service if the application is provided and checks a crafted invalid SVG string CVE-2021-29622 — prometheus: open redirect under the /new endpoint CVE-2021-33194 — golang: x/net/html: infinite loop in ParseFragment

🎯 Affected products200

  • Red Hat OpenShift Container Platform 4.8
  • openshift4/driver-toolkit-rhel8@sha256:0611f98c3661c11ef3d32b11ac0a201c71ff98387f1c37bb92e2009a6731cf74_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/driver-toolkit-rhel8@sha256:1aa3d1eaae7847eb426267e7cce8d780827508812aa8ee31b73703a4902c8c45_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/driver-toolkit-rhel8@sha256:62782792dda0723bf2ce9125bc7ff2cf6c56c206191341b5407ad45e4efdda3d_s390x as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/egress-router-cni-rhel8@sha256:893f246a8d18e04e937d83512d93dfd86faa8406e9f0d12cb23f0219ff374728_s390x as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/egress-router-cni-rhel8@sha256:d1f47253ae18398e71c927b0883a9f11cf0daf4bd9204007d99a9dd2f255e892_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/egress-router-cni-rhel8@sha256:d458f5825cdd7543d76e05e106aef674b2d2a38fdbff31e0c4d91ba50c0351fa_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/network-tools-rhel8@sha256:49330942796a6fbf20fa04925b4a7144424901a805a2dcbd306ec8f852e2799f_s390x as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/network-tools-rhel8@sha256:83a6fbcdd1fcc9c80002a35a311e16198b5d0db1628e42e879648485cbd57448_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/network-tools-rhel8@sha256:cdf3d79f39eadae247e16c745a09246bd9776cd3c540ca367d02f67bb22ccd58_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:624d55a7e3a6b83e9322192bbd9d5a28a574bb033bd2617a505457a66249f649_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:8379b35b375326432fad0a09fcea945b9a40368f50c646ad5bd6dff0385e5b3e_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-aws-machine-controllers@sha256:87dc85e2a15422c53eaad9cbef9dd22f0d3d8f3bcbd144c7ca93f191b217edc1_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:fabf6258e2a624aae154b10a80ea5560709142e2ed60c30438fbcfdeb765d089_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:f1594b52803f381e31340fb3f3c705ee5b8a9b8f3065036e9eced986ddc8ffcb_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-azure-disk-csi-driver-rhel8@sha256:d1f58869b8115480c4af3644d61fd9cd5a17dbab019b77a13a48fd86cf834791_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-azure-machine-controllers@sha256:19392a56764a0abf21bbc8f7c21773298845150de120bb56ba9ea65f7ab02c9f_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-baremetal-installer-rhel8@sha256:9cc9cb3cc72dc940782388e7ad77f60d4f784707a61efea4cce459af53fccbdb_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-baremetal-installer-rhel8@sha256:c300417e52e0c9783fd5f1621fc9f079be2dd588bd15df64f83c81e7d99160e8_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-baremetal-installer-rhel8@sha256:c8a76aacd6c474afebc0d5c3606e7d90abba716b649468f7b0b84a6c9cf2391e_s390x as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-baremetal-machine-controllers@sha256:0978e7c07c82c98fa9768d9ef2e2656a97903fa84503208d25857f8729471c9d_s390x as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-baremetal-machine-controllers@sha256:bd46907fbb20633ef1f5cb366af67217feca89a55c6d6d1c4a65b2ec5af1fdfd_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-baremetal-machine-controllers@sha256:d36c8482b56b62fc5ce85a61e50b9d98f2e92da5a6de5f03ea4579682ac326c0_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-baremetal-rhel8-operator@sha256:581bab760f26bdca64d165176e37c47864e46ff168d638cba5db94331240622f_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-baremetal-rhel8-operator@sha256:67ca2d7285b536bbca0d0846cc7d4eff3dc2d5f9c67460563815c6a8bb2f9190_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-baremetal-rhel8-operator@sha256:9d9e53bdbe862ddf4fefb91e2612d534a6ae462bd48e17d6862a4b9f98b3a6a4_s390x as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-baremetal-runtimecfg-rhel8@sha256:4c5e3ef367cf42bedd6014eda8d6b53b43fee573d191f390d40b9d0031671b7e_s390x as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-baremetal-runtimecfg-rhel8@sha256:a3d602b94395ab01073d0f2bf68cb64f16087de4fa7d1acf55eae109e9819dde_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-baremetal-runtimecfg-rhel8@sha256:faf2ae4b1dc40d82a2eac202776d92ec903a76335e0af9415aaec279ed038913_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • openshift4/ose-cli-artifacts@sha256:198cde90b2f9ab9f30f4aa84f1945502b8d06384730310a2bc3b02f35e6e53ef_amd64 as a component of Red Hat OpenShift Container Platform 4.8
  • +170 more not shown

✅ Remediation

For OpenShift Container Platform 4.8 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.8/updating/updating-cluster-cli.html Workaround: 1.SSL/TLS configurations should prefer AES over DES. Versions of OpenSSL shipped with Red Hat Enterprise Linux 6 and 7 already do so. In the version of OpenSSL shipped with Red Hat Enterprise Linux 5, 3DES is listed below the AES-256 cipher and above the AES-128 cipher, therefore AES-256 based ciphersuite should not be disabled on the server. 2. Servers using OpenSSL, should not disable AES-128 and AES-256 ciphersuites. Versions of Apache shipped with Red Hat Enterprise Linux use the default cipher string, in which AES is preferred over DES/3DES based ciphersuites. For JBoss Middleware, and Java mitigations, please review this knowledge base article: https://access.redhat.com/articles/2598471 This can be mitigated on OpenShift Container Platform (OCP) by disabling the vulnerable TLS cipher suite in the applicable component. TLS configuration options for OCP are described here: https://access.redhat.com/articles/5348961

🔗 References (1724)