RHSA-2023:2138MediumCVSS 8.2

Red Hat Security Advisory: OpenShift Container Platform 4.13.0 CNF vRAN extras security update

Published
May 18, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2020-16251 — vault: GCP Auth Method Allows Authentication Bypass CVE-2021-43998 — vault: incorrect policy enforcement

🎯 Affected products9

  • Red Hat OpenShift Container Platform 4.13
  • openshift4/bare-metal-event-relay-operator-bundle@sha256:e5aacacba93bce05c7a0b3025a8938bc431547d59c6d7dfc8959c3d3d830994e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/bare-metal-event-relay-rhel8-operator@sha256:05878d585437063c8098efe5cd8b0ebd67412e51aea21f7abc063f8d046690e6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/baremetal-hardware-event-proxy-rhel8@sha256:c24fdab236d367bf677f997f8e48ba2c34b922f3816363a8407d4dca8c170819_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/topology-aware-lifecycle-manager-operator-bundle@sha256:6adbc00c12329abfcdb5d30b56162678204a87df6df88933b7a8f08b34118722_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/topology-aware-lifecycle-manager-precache-rhel8@sha256:c92ed15f1540e88f891723e4ae9168462be9597195aaf600be62c422bcdbca65_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/topology-aware-lifecycle-manager-recovery-rhel8@sha256:9e9f24aa00d818b1915362aa9bddf8f504d574e7df43eb894e2d7fdd95948f16_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/topology-aware-lifecycle-manager-rhel8-operator@sha256:3a3a3b6a09934c55325019d249cd064efcacd1140e228a10b566e2ba25e94b0e_amd64 as a component of Red Hat OpenShift Container Platform 4.13
  • openshift4/ztp-site-generate-rhel8@sha256:9d45f3b7e69485083a46433a03f36abfc8728c79384fd6a13b7ca710fc9a967e_amd64 as a component of Red Hat OpenShift Container Platform 4.13

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258

🔗 References (35)