Red Hat Security Advisory: OpenShift Container Platform 4.10.51 security update
🔗 CVE IDs covered (23)
📋 Description
CVE-2020-7692 — google-oauth-client: missing PKCE support in accordance with the RFC for OAuth 2.0 for Native Apps can lead to improper authorization CVE-2022-25857 — snakeyaml: Denial of Service due to missing nested depth limitation for collections CVE-2022-30946 — plugin: CSRF vulnerability in Script Security Plugin CVE-2022-30952 — plugin: User-scoped credentials exposed to other users by Pipeline SCM API for Blue Ocean Plugin CVE-2022-30953 — plugin: CSRF vulnerability in Blue Ocean Plugin CVE-2022-30954 — plugin: missing permission checks in Blue Ocean Plugin CVE-2022-36882 — jenkins-plugin: Cross-site Request Forgery (CSRF) in org.jenkins-ci.plugins:git CVE-2022-36883 — plugin: Lack of authentication mechanism in Git Plugin webhook CVE-2022-36884 — plugin: Lack of authentication mechanism in Git Plugin webhook CVE-2022-36885 — plugin: Non-constant time webhook signature comparison in GitHub Plugin CVE-2022-43401 — jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin CVE-2022-43402 — jenkins-plugin/workflow-cps: Sandbox bypass vulnerabilities in Pipeline: Groovy Plugin CVE-2022-43403 — jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin CVE-2022-43404 — jenkins-plugin/script-security: Sandbox bypass vulnerabilities in Jenkins Script Security Plugin CVE-2022-43405 — jenkins-plugin/pipeline-groovy-lib: Sandbox bypass vulnerability in Pipeline: Groovy Libraries Plugin CVE-2022-43406 — jenkins-plugin/workflow-cps-global-lib: Sandbox bypass vulnerability in Pipeline: Deprecated Groovy Libraries Plugin CVE-2022-43407 — jenkins-plugin/pipeline-input-step: CSRF protection for any URL can be bypassed in Pipeline: Input Step Plugin CVE-2022-43408 — jenkins-plugin/pipeline-stage-view: CSRF protection for any URL can be bypassed in Pipeline: Stage View Plugin CVE-2022-43409 — jenkins-plugin/workflow-support: Stored XSS vulnerability in Pipeline: Supporting APIs Plugin CVE-2022-45047 — mina-sshd: Java unsafe deserialization vulnerability CVE-2022-45379 — jenkins-plugin/script-security: Whole-script approval in Script Security Plugin vulnerable to SHA-1 collisions CVE-2022-45380 — jenkins-plugin/JUnit: Stored XSS vulnerability in JUnit Plugin CVE-2022-45381 — jenkins-plugin/pipeline-utility-steps: Arbitrary file read vulnerability in Pipeline Utility Steps Plugin
🎯 Affected products19
- Red Hat OpenShift Container Platform 4.10
- cri-o-0:1.23.5-5.rhaos4.10.gitd9dec98.el7.src as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-0:1.23.5-5.rhaos4.10.gitd9dec98.el7.x86_64 as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-0:1.23.5-5.rhaos4.10.gitd9dec98.el8.aarch64 as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-0:1.23.5-5.rhaos4.10.gitd9dec98.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-0:1.23.5-5.rhaos4.10.gitd9dec98.el8.s390x as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-0:1.23.5-5.rhaos4.10.gitd9dec98.el8.src as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-0:1.23.5-5.rhaos4.10.gitd9dec98.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-debuginfo-0:1.23.5-5.rhaos4.10.gitd9dec98.el7.x86_64 as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-debuginfo-0:1.23.5-5.rhaos4.10.gitd9dec98.el8.aarch64 as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-debuginfo-0:1.23.5-5.rhaos4.10.gitd9dec98.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-debuginfo-0:1.23.5-5.rhaos4.10.gitd9dec98.el8.s390x as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-debuginfo-0:1.23.5-5.rhaos4.10.gitd9dec98.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-debugsource-0:1.23.5-5.rhaos4.10.gitd9dec98.el8.aarch64 as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-debugsource-0:1.23.5-5.rhaos4.10.gitd9dec98.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-debugsource-0:1.23.5-5.rhaos4.10.gitd9dec98.el8.s390x as a component of Red Hat OpenShift Container Platform 4.10
- cri-o-debugsource-0:1.23.5-5.rhaos4.10.gitd9dec98.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.10
- jenkins-2-plugins-0:4.10.1675144701-1.el8.noarch as a component of Red Hat OpenShift Container Platform 4.10
- jenkins-2-plugins-0:4.10.1675144701-1.el8.src as a component of Red Hat OpenShift Container Platform 4.10
✅ Remediation
For OpenShift Container Platform 4.10 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.10/release_notes/ocp-4-10-release-notes.html Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Restrict the ability to configure Jenkins Pipelines to trusted users only. Upgrade to Jenkins Pipeline: Stage View Plugin version 2.27 or later, which correctly encodes input step IDs in generated URLs. Workaround: From the maintainer: For Apache MINA SSHD <= 2.9.1, do not use org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider to generate and later load your server's host key. Use separately generated host key files, for instance in OpenSSH format, and load them via a org.apache.sshd.common.keyprovider.FileKeyPairProvider instead. Or use a custom implementation instead of SimpleGeneratorHostKeyProvider that uses the OpenSSH format for storing and loading the host key (via classes OpenSSHKeyPairResourceWriter and OpenSSHKeyPairResourceParser).
🔗 References (26)
- selfhttps://access.redhat.com/errata/RHSA-2023:0560
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1856376
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2116840
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119643
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119646
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119647
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119656
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119657
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119658
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2126789
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136370
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136374
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136379
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136381
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136382
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136383
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136386
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136388
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2136391
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2143086
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2143089
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2143090
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2145194
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0560.json