RHSA-2023:1328MediumCVSS 7.5
Red Hat Security Advisory: OpenShift Container Platform 4.13.0 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2021-20329 — mongo-go-driver: specific cstrings input may not be properly validated CVE-2021-38561 — golang: out-of-bounds read in golang.org/x/text/language leads to DoS CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests
🎯 Affected products179
- Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:06be20909f0d3b0baf04c54c0367fcca9d212b76796c1dce6949b5e78f37776b_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:10f3da0fbb65b9ed4ade660493b3dba0e1a48a261fad0b68b0802936997c6bed_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:ab2c145d92489d1f01e7ad0d1fa1be96dcbe73e718cd3ce64f55057fd3fb3871_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:c578b4984646b082165e76407c00dc1eee4d03716a6974be7086215a34bc4d62_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/dpu-network-operator-bundle@sha256:8d81fa29dd6c81a5c42e470d4892c6498b617452c547437fbda52f025f0c8da3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/dpu-network-rhel8-operator@sha256:4f3a116666a7a1bb3bf8070df0a6a7d967059a0b883123a40d9d20b41419dfeb_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/dpu-network-rhel8-operator@sha256:e7a0706fbf0ca433d0511cdf5e2b4d41231878817a35d765e69449aa3be289d2_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:115a244e7468127d3deae0ae33aa747f581e288dc5a0223d04e377e843e6ba46_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:75afa729a8d90ecea197abdded27d24901f417bc4b7c994e8b8015eb5915350b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:cc2e031907d97d3de073224e518f7c6a811030612b40bda9005e85d00c6aa175_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:fe6e8e7231b2802c85ff1eba6f0685cb390470295718cb1bf5e555b0f5c615f2_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-operator-bundle@sha256:d9f0d59273f664eb8224e21654e4cd72ae2edcfb288c9c5fcb2b19ad8bac01cc_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:0468f6b8e0c6c0ae7af617094624e560c1c9eee2bde4da0cdb8fb99d851e97db_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:8fdb9b5bd82e07eceac6f2697acc5566d247381dcf208de72ba6e988f860bd88_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:b747431120b1ff6df3114097bbd1c869d5827bc42e21af43f5e638432e190ec2_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:b90319aefb5eebba2974526eccbb3d96bba4068c72f457ae6b3a0773890e36b0_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:3522e03791c147c19df69bee3ca308de26db56a3c1060bfaf65d1ccdc297e5b9_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:3e9800e6f49a2e5c87b28b0ce79878a69ce85bccb4b29a6ec8754d3dd63126b3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:94c5f1ff554ca370307519ff96433cd1c1e17df77007b6efe4ee13d48fa3d7ce_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:cf5fa06406e38936d52d4e965f8007e6be530ce2db228ca74a7e13b2998cbddd_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-operator-bundle@sha256:d2ab488f729166bbb9ae586f428a78568be84fd0d96187902f35b0fadff28587_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:36b9fa6c1e41906783d9ad33e5978e4a26bd412f95f5df817557c21d5c81b3a8_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:8e20966d506c3f6502b9a4252a6912e592008fe840b29acfe9c2656b89ffc112_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:9cae392ff4ec2eafd35c2100388acac0a70f3f769e8e4d8b912b25cbdd5e9b3e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:b56f788f9a30e62ebd9c99ed1d0c0b86d61bb4f65dffd910857f9164559e7dae_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:52e2281b10340247dbb78e789f18009e44a97568d32ab1b3a92af27d26a90007_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:96962a001d4dfd16a88c77bf948fb2a673cb1404a3c901dd27d16c90151b267c_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:cb208fa56a4c4782c4f266ea9e283e5cac3afff3f16c5072dbf7a05c37ec5832_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:eb2886bcb12d54453c7fcb9650e7f9ae06be9ad12aad8f05286f7206d3adef73_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- +149 more not shown
✅ Remediation
See the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2023:1328
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1971033
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2100495
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161274
- externalhttps://issues.redhat.com/browse/OCPBUGS-10561
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1328.json