RHSA-2021:2517HighCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 3.11.462 bug fix and security update

Published
June 30, 2021
Last Modified
August 4, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2020-27216 — jetty: local temporary directory hijacking vulnerability CVE-2020-27218 — jetty: buffer not correctly recycled in Gzip Request inflation CVE-2020-27223 — jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS CVE-2021-21642 — jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. CVE-2021-21643 — jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. CVE-2021-21644 — jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability. CVE-2021-21645 — jenkins-2-plugins/config-file-provider: Does not perform permission checks in several HTTP endpoints.

🎯 Affected products85

  • Red Hat OpenShift Container Platform 3.11
  • atomic-enterprise-service-catalog-1:3.11.462-1.git.2e6be86.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-enterprise-service-catalog-1:3.11.462-1.git.2e6be86.el7.src as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-enterprise-service-catalog-1:3.11.462-1.git.2e6be86.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-enterprise-service-catalog-svcat-1:3.11.462-1.git.2e6be86.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-enterprise-service-catalog-svcat-1:3.11.462-1.git.2e6be86.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-0:3.11.462-1.git.0.e7d0362.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-0:3.11.462-1.git.0.e7d0362.el7.src as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-0:3.11.462-1.git.0.e7d0362.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-clients-0:3.11.462-1.git.0.e7d0362.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-clients-0:3.11.462-1.git.0.e7d0362.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-clients-redistributable-0:3.11.462-1.git.0.e7d0362.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-cluster-autoscaler-0:3.11.462-1.git.99b2acf.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-cluster-autoscaler-0:3.11.462-1.git.99b2acf.el7.src as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-cluster-autoscaler-0:3.11.462-1.git.99b2acf.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-descheduler-0:3.11.462-1.git.d435537.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-descheduler-0:3.11.462-1.git.d435537.el7.src as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-descheduler-0:3.11.462-1.git.d435537.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-docker-excluder-0:3.11.462-1.git.0.e7d0362.el7.noarch as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-dockerregistry-0:3.11.462-1.git.3571208.el7.src as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-dockerregistry-0:3.11.462-1.git.3571208.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-excluder-0:3.11.462-1.git.0.e7d0362.el7.noarch as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-hyperkube-0:3.11.462-1.git.0.e7d0362.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-hyperkube-0:3.11.462-1.git.0.e7d0362.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-hypershift-0:3.11.462-1.git.0.e7d0362.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-hypershift-0:3.11.462-1.git.0.e7d0362.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-master-0:3.11.462-1.git.0.e7d0362.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-master-0:3.11.462-1.git.0.e7d0362.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-metrics-server-0:3.11.462-1.git.f8bf728.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
  • atomic-openshift-metrics-server-0:3.11.462-1.git.f8bf728.el7.src as a component of Red Hat OpenShift Container Platform 3.11
  • +55 more not shown

✅ Remediation

See the following documentation, which will be updated shortly for release 3.11.462, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258. Workaround: Jetty users should create temp folders outside the normal /tmp structure, and ensure that their permissions are set so as not to be accessible by an attacker. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

🔗 References (17)