RHSA-2022:5673HighCVSS 9.8

Red Hat Security Advisory: Release of containers for OSP 16.2.z director operator tech preview

Published
July 20, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2021-41103 — containerd: insufficiently restricted permissions on container root and plugin directories CVE-2021-43565 — golang.org/x/crypto: empty plaintext packet causes panic CVE-2022-26945 — go-getter: command injection vulnerability CVE-2022-30321 — go-getter: unsafe download (issue 1 of 3) CVE-2022-30322 — go-getter: unsafe download (issue 2 of 3) CVE-2022-30323 — go-getter: unsafe download (issue 3 of 3)

🎯 Affected products4

  • Red Hat OpenStack Platform 16.2
  • rhosp-rhel8-tech-preview/osp-director-downloader@sha256:076a67e9290c311aa8be3c24b4c512957e24c8aab698f1b56469dd5233f408f1_amd64 as a component of Red Hat OpenStack Platform 16.2
  • rhosp-rhel8-tech-preview/osp-director-operator-bundle@sha256:aa9e37b43a57edcad97584248c7a47bb819d3b558520610b0bd4ffaaa800e42d_amd64 as a component of Red Hat OpenStack Platform 16.2
  • rhosp-rhel8-tech-preview/osp-director-operator@sha256:093ae2ef7b3a802a70e1e9e28edaf35a01a76bbc701d00fecdf4bedb9891f022_amd64 as a component of Red Hat OpenStack Platform 16.2

✅ Remediation

OSP 16.2 Release - OSP Director Operator Containers tech preview Workaround: The fix includes new configuration options to help limit the security exposure and have more secure defaults.

🔗 References (11)