Red Hat Security Advisory: OpenShift Container Platform 4.8.49 security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2021-39226 — grafana: Snapshot authentication bypass CVE-2022-26945 — go-getter: command injection vulnerability CVE-2022-30321 — go-getter: unsafe download (issue 1 of 3) CVE-2022-30322 — go-getter: unsafe download (issue 2 of 3) CVE-2022-30323 — go-getter: unsafe download (issue 3 of 3) CVE-2022-30631 — golang: compress/gzip: stack exhaustion in Reader.Read
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.8
- openshift4/driver-toolkit-rhel8@sha256:033f1d6da559e3e5246de6021e06cfd87e27953e2d8dd8cecd8c68fe0a4ba2ba_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/driver-toolkit-rhel8@sha256:3c0383d275c7bdd2db555f5b787463479c4bf11126632ec8e5f2d463e721af82_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/driver-toolkit-rhel8@sha256:fbff024df4a4aa7f690333828aa0afcae1bc6823499ef66bb0055303d105cebd_s390x as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/egress-router-cni-rhel8@sha256:2d7099e0378dd1062d51e4c5426dda7a48ceb7a13587f3f361e19da94679d92e_s390x as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/egress-router-cni-rhel8@sha256:508ed5c3a5b9f1ae96006f43903cf06c15b708d505a71c5e668b6b635d60b9d5_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/egress-router-cni-rhel8@sha256:62fa1517fc67d5c1fd7315966163845681ab3cedc706640e69bd5e0487c64e5a_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/network-tools-rhel8@sha256:1f11f67671ae0aa456f6ebebef4f09d5ba2998577aa08cec1c47ebcea9b482c8_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/network-tools-rhel8@sha256:cfa5ccebec7b2fe262ec6cef8598a30dba4733c774a372d5d5b8fe22811e7e70_s390x as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/network-tools-rhel8@sha256:d28a82a5daab3ec66220cc5f3c966ad56ce9a4a93711bbe606cd7bd8ddeb447d_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:8a99c761722ca2a763d7edfd12a2f3d216f28a28856ecf4049d1e5e218ad737a_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-aws-ebs-csi-driver-rhel8@sha256:910eca9e0cdaadee58a0360ed89a04d78b898a81df26301f751a7dc870bcb7be_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-aws-machine-controllers@sha256:2627bf66c9a6adc38187884ecb9f196d369cffb96dfb58a08629333a77f2909a_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-aws-pod-identity-webhook-rhel8@sha256:5e5a59514177315ebff749b95d5a2f0f635eed4b51efd9ea8da1c99250175772_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-azure-disk-csi-driver-rhel8-operator@sha256:707ec532cdf4fd0d061179a20849028e6b73e9f035c6b01ffebe63e38beb142d_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-azure-disk-csi-driver-rhel8@sha256:2b5748463b29625dd40e1be8d437aa2c7f3aa707a6e49ec169545c3855408861_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-azure-machine-controllers@sha256:2ca52be9a6045560ac4570e5627b8d57ac47590bef7c0b35e5e13d4165933ec7_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-baremetal-installer-rhel8@sha256:8b76a6a8ec1c808f7fedbb9e294c0b5c53c5b3c3e5fbe6195f15a2061840114a_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-baremetal-installer-rhel8@sha256:956a292579ed1630be9d964cea17aa2e16419d8736a61dd725d22c56447a949d_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-baremetal-installer-rhel8@sha256:cc2ecdcc49a922eed3e754656ba5459c866fe391570ce37e8e4d411b09164fe6_s390x as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-baremetal-machine-controllers@sha256:2e9382d9c3dc7e74f4f510960aa4102e07f33554319a1c2cb4281dc19bd8cb33_s390x as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-baremetal-machine-controllers@sha256:4ba4d8474b3db12ec93c040c5398044a8a2808cc96f8ee2e929df7514b40d4f9_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-baremetal-machine-controllers@sha256:f7eb07b45441db3b048645032dcb4dc413c500bb04d9380eadac60f902795763_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-baremetal-rhel8-operator@sha256:19989350cd69ab3137ee6cb76f01f1ab193c0f5660fab4d8bc69500f06ccc044_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-baremetal-rhel8-operator@sha256:7cb7caa78cd357847afb6a97dd1aef60780d2d546dc64668643137d38b34a5f1_s390x as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-baremetal-rhel8-operator@sha256:fee3eaaae7f8e765d33d4b0ee4792fb95828fd033543f4490ea97a20edbc5cc1_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:5855cc5a9dcdfb75649eea0f4b94e2ce2fc0193471a6d2a63343f647e201204f_s390x as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:727564f4ea1eb7d8313118041e2dfa1bd3ef8f37902fbd2de2450307d93a0810_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-baremetal-runtimecfg-rhel8@sha256:ef493e7c10751e19e3573c5dbfa8f87a170310aaa0c7e88bf915d15bf053bc05_ppc64le as a component of Red Hat OpenShift Container Platform 4.8
- openshift4/ose-cli-artifacts@sha256:6ba5dc950b5f24c07717705e3d395d35750f9ba7727afb52eb33600a9d874fb0_amd64 as a component of Red Hat OpenShift Container Platform 4.8
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.8 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.8/updating/updating-cluster-cli.html Workaround: The fix includes new configuration options to help limit the security exposure and have more secure defaults.
🔗 References (21)
- selfhttps://access.redhat.com/errata/RHSA-2022:6308
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1881882
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1959706
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1991938
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2011063
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064860
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092918
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092923
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092925
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2092928
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2095210
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2098252
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2105159
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107342
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2112999
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2113998
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2115039
- externalhttps://issues.redhat.com/browse/OCPBUGS-580
- externalhttps://issues.redhat.com/browse/OCPBUGS-604
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_6308.json