RHSA-2022:5673HighCVSS 9.8
Red Hat Security Advisory: Release of containers for OSP 16.2.z director operator tech preview
🔗 CVE IDs covered (6)
📋 Description
CVE-2021-41103 — containerd: insufficiently restricted permissions on container root and plugin directories CVE-2021-43565 — golang.org/x/crypto: empty plaintext packet causes panic CVE-2022-26945 — go-getter: command injection vulnerability CVE-2022-30321 — go-getter: unsafe download (issue 1 of 3) CVE-2022-30322 — go-getter: unsafe download (issue 2 of 3) CVE-2022-30323 — go-getter: unsafe download (issue 3 of 3)
🎯 Affected products4
- Red Hat OpenStack Platform 16.2
- rhosp-rhel8-tech-preview/osp-director-downloader@sha256:076a67e9290c311aa8be3c24b4c512957e24c8aab698f1b56469dd5233f408f1_amd64 as a component of Red Hat OpenStack Platform 16.2
- rhosp-rhel8-tech-preview/osp-director-operator-bundle@sha256:aa9e37b43a57edcad97584248c7a47bb819d3b558520610b0bd4ffaaa800e42d_amd64 as a component of Red Hat OpenStack Platform 16.2
- rhosp-rhel8-tech-preview/osp-director-operator@sha256:093ae2ef7b3a802a70e1e9e28edaf35a01a76bbc701d00fecdf4bedb9891f022_amd64 as a component of Red Hat OpenStack Platform 16.2
✅ Remediation
OSP 16.2 Release - OSP Director Operator Containers tech preview Workaround: The fix includes new configuration options to help limit the security exposure and have more secure defaults.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2022:5673
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/errata/RHSA-2022:4991
- externalhttps://access.redhat.com/containers
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011007
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2030787
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092918
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092923
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092925
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092928
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_5673.json