Red Hat Security Advisory: OpenShift Container Platform 3.11.462 bug fix and security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2020-27216 — jetty: local temporary directory hijacking vulnerability CVE-2020-27218 — jetty: buffer not correctly recycled in Gzip Request inflation CVE-2020-27223 — jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS CVE-2021-21642 — jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. CVE-2021-21643 — jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. CVE-2021-21644 — jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnerability. CVE-2021-21645 — jenkins-2-plugins/config-file-provider: Does not perform permission checks in several HTTP endpoints.
🎯 Affected products85
- Red Hat OpenShift Container Platform 3.11
- atomic-enterprise-service-catalog-1:3.11.462-1.git.2e6be86.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-enterprise-service-catalog-1:3.11.462-1.git.2e6be86.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- atomic-enterprise-service-catalog-1:3.11.462-1.git.2e6be86.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-enterprise-service-catalog-svcat-1:3.11.462-1.git.2e6be86.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-enterprise-service-catalog-svcat-1:3.11.462-1.git.2e6be86.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-0:3.11.462-1.git.0.e7d0362.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-0:3.11.462-1.git.0.e7d0362.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-0:3.11.462-1.git.0.e7d0362.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-clients-0:3.11.462-1.git.0.e7d0362.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-clients-0:3.11.462-1.git.0.e7d0362.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-clients-redistributable-0:3.11.462-1.git.0.e7d0362.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-cluster-autoscaler-0:3.11.462-1.git.99b2acf.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-cluster-autoscaler-0:3.11.462-1.git.99b2acf.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-cluster-autoscaler-0:3.11.462-1.git.99b2acf.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-descheduler-0:3.11.462-1.git.d435537.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-descheduler-0:3.11.462-1.git.d435537.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-descheduler-0:3.11.462-1.git.d435537.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-docker-excluder-0:3.11.462-1.git.0.e7d0362.el7.noarch as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-dockerregistry-0:3.11.462-1.git.3571208.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-dockerregistry-0:3.11.462-1.git.3571208.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-excluder-0:3.11.462-1.git.0.e7d0362.el7.noarch as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-hyperkube-0:3.11.462-1.git.0.e7d0362.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-hyperkube-0:3.11.462-1.git.0.e7d0362.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-hypershift-0:3.11.462-1.git.0.e7d0362.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-hypershift-0:3.11.462-1.git.0.e7d0362.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-master-0:3.11.462-1.git.0.e7d0362.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-master-0:3.11.462-1.git.0.e7d0362.el7.x86_64 as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-metrics-server-0:3.11.462-1.git.f8bf728.el7.ppc64le as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-metrics-server-0:3.11.462-1.git.f8bf728.el7.src as a component of Red Hat OpenShift Container Platform 3.11
- +55 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for release 3.11.462, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/3.11/release_notes/ocp_3_11_release_notes.html This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258. Workaround: Jetty users should create temp folders outside the normal /tmp structure, and ensure that their permissions are set so as not to be accessible by an attacker. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2021:2517
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1891132
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1902826
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1929718
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1934116
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944916
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1952146
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1952148
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1952151
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1952152
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1962884
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1965827
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1973109
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1973123
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1974623
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_2517.json