Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.11.0 security, enhancement, & bugfix update
🔗 CVE IDs covered (19)
📋 Description
CVE-2021-23440 — nodejs-set-value: type confusion allows bypass of CVE-2019-10747
CVE-2021-23566 — nanoid: Information disclosure via valueOf() function
CVE-2022-0235 — node-fetch: exposure of sensitive information to an unauthorized actor
CVE-2022-0536 — follow-redirects: Exposure of Sensitive Information via Authorization Header leak
CVE-2022-1650 — eventsource: Exposure of Sensitive Information
CVE-2022-21698 — prometheus/client_golang: Denial of service using InstrumentHandlerCounter
CVE-2022-23772 — golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString
CVE-2022-23773 — golang: cmd/go: misinterpretation of branch names can lead to incorrect access control
CVE-2022-23806 — golang: crypto/elliptic: IsOnCurve returns true for invalid field elements
CVE-2022-24675 — golang: encoding/pem: fix stack overflow in Decode
CVE-2022-24771 — node-forge: Signature verification leniency in checking digestAlgorithm structure can lead to signature forgery
CVE-2022-24772 — node-forge: Signature verification failing to check tailing garbage bytes can lead to signature forgery
CVE-2022-24773 — node-forge: Signature verification leniency in checking DigestInfo structure
CVE-2022-24785 — Moment.js: Path traversal in moment.locale
CVE-2022-24921 — golang: regexp: stack exhaustion via a deeply nested expression
CVE-2022-28327 — golang: crypto/elliptic: panic caused by oversized scalar
CVE-2022-29526 — golang: syscall: faccessat checks wrong group
CVE-2022-29810 — go-getter: writes SSH credentials into logfile, exposing sensitive credentials to local uses
CVE-2022-31129 — moment: inefficient parsing algorithm resulting in DoS
🎯 Affected products79
- RHODF 4.11 for RHEL 8
- odf4/cephcsi-rhel8@sha256:3f7fbeb56a29d3e23855368a1fca0cf86d055e4d9ff0fe387eae1ae3bf266056_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/cephcsi-rhel8@sha256:b795c0b44236237d5efca90eb9e2786a9b3e82968d5022eaed8848c7f49bb38d_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/cephcsi-rhel8@sha256:c45d178764106cb22cdc5f9adb354ea11211712e5be93b7a067d28f410067f0c_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-core-rhel8@sha256:25e9cf317088b7a827629cb40ee7f816994b465e86f3b2df5a97931cfa4eb40d_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-core-rhel8@sha256:ab449f9f9aa1df48e076c283b19f32361ee5d531ffe13922401107095814708d_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-core-rhel8@sha256:d675998c5c475f799e937a3f90e59813d583e8f84a7f6759298ba92e50a9c288_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-operator-bundle@sha256:0595b90d21f7a5a0ea91a11492f1dbfbe2759ecd9707a8e9e4953d57c973f801_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-operator-bundle@sha256:4c9db259686a6de3247892d1ec915d185d5276e0d4de3545e4cf81ec8310c87d_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-operator-bundle@sha256:645eaf6f2412322d28789021b9393fb368156c4f2aa14528fe9209e3c22fe475_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-rhel8-operator@sha256:257eb2ca9f59ff15db9018038422382a6887b82c603515cd1b2b12781fbb189a_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-rhel8-operator@sha256:8d7d066a645cade7d01ecd3d0427cbadca889dc8c1a3ffde1f4193b777975c75_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-rhel8-operator@sha256:fc2c495c5236268e095265dd202587ab7bcf376b14a1e4d05875f5e053635cb0_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-metrics-exporter-rhel8@sha256:261691407d9e36597d6de3fb2d7707f78ea9cdd91f6f674f86cfd9727c3ce739_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-metrics-exporter-rhel8@sha256:6e447521417d9331f471ed77645354406adf47b94497c5f8f13a8966e6534cec_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-metrics-exporter-rhel8@sha256:9068cccd15cbe2c2c36c4a5633f704616653dc735256d78f588ec6e2b7e1e612_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-must-gather-rhel8@sha256:012fcf6f037110f56be4a72bb48ede013b764a0ee4615718d985397cafe11129_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-must-gather-rhel8@sha256:83b0764e21d3a1d2b4efe26bed9a3fdfe4b370ec9f7c4e2bf9cee44a9c33c5bb_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-must-gather-rhel8@sha256:8d177becb51a16957264e508d623fa2c0f11505b3819b306f39da154db947d91_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-operator-bundle@sha256:088b8dc1d459270629610aab02666f99262c9675336d812b24e43df135d9e96a_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-operator-bundle@sha256:0f61780f3b698672e76029d705abd69349cd01782626f66e9fd029be71b9c336_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-operator-bundle@sha256:4506d1dc937411d88d435e23b7bfd17cc48d04e237f697f0cb8d9da6c4b3daf4_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-rhel8-operator@sha256:57947da5535936416a10a9de871aa37dd69e157b762577ba30b7f8d1332eb644_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-rhel8-operator@sha256:717c291c0eae097da0432f36efc4c070c9e1fc3824344ad6ccac254a720fac05_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-rhel8-operator@sha256:ebe1cd859b8483554955c12229be987622825fb292f522a50e2d8c289c53cd65_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/odf-console-rhel8@sha256:a5fa14675b15c4e59ab9717051e3de0692e36baab909af1409075c7e85402c26_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/odf-console-rhel8@sha256:aa873670a03cda9fb7a56130f0be4f827dafe4aba7d00833f7020f8ce0a978ae_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/odf-console-rhel8@sha256:e7055ac1518d19cd288af0a829f8e28fd1eef92e3e03044225b4c9b204e4d1e8_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/odf-csi-addons-operator-bundle@sha256:4776158851b33c146ef13f861d59db2340e74f86c35dfc6ab08f2fb7e2455a3b_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/odf-csi-addons-operator-bundle@sha256:74a8060b385b219f44eca200ca1e9e59006ea65fa8b3179b82511ccf94109134_ppc64le as a component of RHODF 4.11 for RHEL 8
- +49 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Sanitize the user-provided locale name before passing it to Moment.js.
🔗 References (139)
- selfhttps://access.redhat.com/errata/RHSA-2022:6156
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com//documentation/en-us/red_hat_openshift_data_foundation/4.11/html/4.11_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1937117
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1947482
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1973317
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1996829
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2004944
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2027724
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2029298
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044591
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2045880
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2047173
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2050853
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2050897
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053259
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053429
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053532
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053541
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2056697
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2058211
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2060487
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2060790
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2061713
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2063691
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064426
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064857
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2066514
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2067079
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2067387
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2067458
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2067461
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2069314
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2069319
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2069812
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2069815
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2070542
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2071494
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2072009
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2073920
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2074810
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2075426
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2075581
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2076457
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2077242
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2077688
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2077689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2079866
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2079873
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2080279
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2081680
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2082028
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2082078
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2082497
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2083074
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2083441
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2083953
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2083993
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2084041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2084085
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2084201
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2084503
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2084546
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2084565
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2085307
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2085351
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2085357
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2086557
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2086675
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2086982
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2086983
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2087078
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2087107
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2087237
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2087675
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2087732
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2087755
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088359
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088380
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088506
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088587
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089342
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089397
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089552
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089567
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089786
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089795
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2089797
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2090278
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2090314
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2090953
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2091487
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2091638
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2091641
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2091681
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2091894
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2091951
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2091998
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092217
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092220
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092349
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092372
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092400
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2093266
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2093848
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2094179
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2094853
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2094856
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2095155
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2096209
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2096414
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2096509
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2096513
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2096823
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2096937
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2097216
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2097287
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2097305
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2098121
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2098261
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2098536
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2099265
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2099581
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2099609
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2099646
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2099660
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2099724
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2099965
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2100326
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2100352
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2100946
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2101139
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2101380
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2103818
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2104833
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105075
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6156.json