Red Hat Security Advisory: OpenShift Container Platform 4.8.56 packages and security update
🔗 CVE IDs covered (16)
📋 Description
CVE-2022-2048 — http2-server: Invalid HTTP/2 requests cause DoS CVE-2022-29047 — Libraries: Untrusted users can modify some Pipeline libraries in Pipeline Shared Groovy Libraries Plugin CVE-2022-30945 — plugin: Sandbox bypass vulnerability through implicitly allowlisted platform Groovy files in Pipeline: Groovy Plugin CVE-2022-30946 — plugin: CSRF vulnerability in Script Security Plugin CVE-2022-30948 — plugin: Mercurial SCM plugin can check out from the controller file system CVE-2022-30952 — plugin: User-scoped credentials exposed to other users by Pipeline SCM API for Blue Ocean Plugin CVE-2022-30953 — plugin: CSRF vulnerability in Blue Ocean Plugin CVE-2022-30954 — plugin: missing permission checks in Blue Ocean Plugin CVE-2022-34174 — jenkins: Observable timing discrepancy allows determining username validity CVE-2022-34176 — jenkins-plugin/junit: Stored XSS vulnerability in JUnit Plugin CVE-2022-34177 — jenkins-plugin: Arbitrary file write vulnerability in Pipeline Input Step Plugin CVE-2022-36881 — jenkins-plugin: Man-in-the-Middle (MitM) in org.jenkins-ci.plugins:git-client CVE-2022-36882 — jenkins-plugin: Cross-site Request Forgery (CSRF) in org.jenkins-ci.plugins:git CVE-2022-36883 — plugin: Lack of authentication mechanism in Git Plugin webhook CVE-2022-36884 — plugin: Lack of authentication mechanism in Git Plugin webhook CVE-2022-36885 — plugin: Non-constant time webhook signature comparison in GitHub Plugin
🎯 Affected products5
- Red Hat OpenShift Container Platform 4.8
- jenkins-0:2.361.1.1672840472-1.el8.noarch as a component of Red Hat OpenShift Container Platform 4.8
- jenkins-0:2.361.1.1672840472-1.el8.src as a component of Red Hat OpenShift Container Platform 4.8
- jenkins-2-plugins-0:4.8.1672842762-1.el8.noarch as a component of Red Hat OpenShift Container Platform 4.8
- jenkins-2-plugins-0:4.8.1672842762-1.el8.src as a component of Red Hat OpenShift Container Platform 4.8
✅ Remediation
For OpenShift Container Platform 4.8 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.8/updating/updating-cluster-cli.html
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2023:0017
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2074855
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2103548
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2103551
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2114755
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2116840
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2116952
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119642
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119643
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119644
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119646
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119647
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119653
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119656
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119657
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119658
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0017.json