Red Hat Security Advisory: OpenShift Container Platform 4.12.16 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-46146 — exporter-toolkit: authentication bypass via cache poisoning
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:35e37faa1d1a62f24a23f1c70dc80b9b603757c8a46ea25c2df887f5352e1c7c_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:4c20578d11d552b005c7495ecc493fca5d5349c68928e799638186325f030881_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:6d322355968d5bfc205d22940befc390bfcbfdd87657ccafe47684e8876bc046_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:95b6b5d0b3b4bde379fbc14cd3ee63f1990cc0dd8aa63b78f5df479b5afb17c8_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:52544fa1d2d37f7a6403259d752f34d73cf11d77bcd66edbbdfc6725a681ea4f_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:9f20f58cccc85f70273b878171193c73e51160931f3c9082b2d0cd3353db5d32_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:a33cb4f0e89f0cdab28cc7e7312986020b5802c0bfcd2215b95f2721bc47b236_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:b15009bbd00ac617c84e707a15754e845cde19bd06c6519b2bd4a248afb84782_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:3d80fde18a71fcda00fa421418e9fec24477399c3fe3267e5a4b2a40a1d80e40_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:43cbfa631ae2d3146e6aae648eacc367c655adffe00b560ea45201b73d97963d_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:723f445c78f6136fe0cd71e570638ac8f9129864fdbaf1dc3446c8d0af2fe706_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:905c1ecac13dae89519a6437ca5bdb87afd66a92cfc32c1075baccba65b854c7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:46b9e657c3906b88e967f169f5a75c61d508ebac14c0fd78c05d48ca3af63fdd_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:a308367a7d4238f900461f7d76915a5f56ac12859632dd27dbeed8560abb5c28_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:cddcb0d2b5fa669755415f6dc19c5de504bfe74847bb7f2a60fe47ecb34a750d_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:f94fd4e0ee09e28c22708a7e96b19a9f8eb3539b24bb2493008e237d6ffd778b_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:4c04e1883ac61204dc578e26db5f582a5e55e9856e49b3b15d364e38ca6d1a33_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:60294e80578f5521af48e767f15822c6964bf1afd8dc5026f7a5f9e9de9e5dbd_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:969bd11183736474739ad21712eedd39509b3caade61310363b85a9f430a42b3_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:ab18f805cf945221dfcb7d65947b1e53c48b181dbffafbd70d2a40a2d5ffb13f_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/oc-mirror-plugin-rhel8@sha256:8565493d92863219e49d27e695c4b13f5384e10a53074ea27d2d64f124160fda_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:383262b0b9fa320816460dc69a99400af831ad779064c431f68b0d17efa76bbf_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:79770fc878c4bbf3c17d78a5fbae46b851ba481665e2244937e697baf933aae4_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:ab08c4b464d3b2d20c5704b671a473d29d9e1ef36541ee005c7a1d0f1414c9ac_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:cf8f6345acdd8f480d9a4b9cb2b6ea966a47f683ed8d75ddf4153f3ed66b7e6e_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:5e82ea79719b8bd4db4d0687fcc99d5fc154c431cb98a738ea79e9594adb77e7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:8a5cb005d926637c1b23706de3d1b833b07c714157096bbbb18788b7fbb8a164_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:95b968674cace8c1fb1de0181a66dd87979b4604c3703767cd15804d7be9da0d_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:b540a1d5e065bc92c3e4bf55b4f3a524da885b813b19422e1d4ba1faae39b78f_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You can download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests can be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:5339b3c4686010dc42990e0addce5aa4fddd071d6d9504dffe08a4b5059f6f38 (For s390x architecture) The image digest is sha256:171c389cac763eb6f77cb088755782bec565357baf655e611f50885f814f1aaf (For ppc64le architecture) The image digest is sha256:de25720325b20112a6361207a6c42a2f5859e6d023fe176410a9e1aaf0ed3c74 (For aarch64 architecture) The image digest is sha256:8794d8a92afa21c8869daba76761deff737126ef9e3377e30173bd826506cc67 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2023:2110
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2149436
- externalhttps://issues.redhat.com/browse/OCPBUGS-11559
- externalhttps://issues.redhat.com/browse/OCPBUGS-11844
- externalhttps://issues.redhat.com/browse/OCPBUGS-11972
- externalhttps://issues.redhat.com/browse/OCPBUGS-11993
- externalhttps://issues.redhat.com/browse/OCPBUGS-12199
- externalhttps://issues.redhat.com/browse/OCPBUGS-12265
- externalhttps://issues.redhat.com/browse/OCPBUGS-12361
- externalhttps://issues.redhat.com/browse/OCPBUGS-12440
- externalhttps://issues.redhat.com/browse/OCPBUGS-12473
- externalhttps://issues.redhat.com/browse/OCPBUGS-12476
- externalhttps://issues.redhat.com/browse/OCPBUGS-12477
- externalhttps://issues.redhat.com/browse/OCPBUGS-12688
- externalhttps://issues.redhat.com/browse/OCPBUGS-1753
- externalhttps://issues.redhat.com/browse/OCPBUGS-6888
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_2110.json