Red Hat Security Advisory: OpenShift Container Platform 4.13.1 bug fix and security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2018-17419 — dns: Denial of Service (DoS) CVE-2021-36157 — cortex: Grafana Cortex directory traversal CVE-2022-41722 — golang: path/filepath: path-filepath filepath.Clean path traversal CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding
🎯 Affected products177
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:21dbf78a949e8b4cb2a8275820ff850d26817ca6809d9276128c8656221f1c85_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:8d60869ea639ff11289c968aa72b04e375e5c0617fbbcce5055c29fa8a950d42_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:a8a083bf94d324298d570fdb2f7067d10ddaf6bdf96ede4945c817ec1b9f7a79_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:efa9f004b443436c6b0d0f53232db36a1e7581337733e09279f7c3ac0f804df6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:afe7c4ffff3b1cd25d6af9c8bd7268e66203affc3dd4bbaf6a2e50bff6f3df9f_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:d9d93761986da3428ad4e9358ba6eff57e165e78feb61517274e16466616161f_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:e2f73efc226ca0e0fae21bec6371d813abf5b568615b39c77edc86bba8ebf736_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:e3b2c3661fc51d56dea4b288ecf6b4280c29a0a46ca1ed90648844cd4b2072da_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:0bf13808d525a1abcdbf8d74af868551ca196d9141e799d325cbe955170b5074_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:45596cd819a80a7b8448422476b902046d74cc4b5d8235514e0094d0396589ae_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:7339582b8bdf73b370a730b070b1ab6ef78aede0a6abc5cfa457207f4f330fde_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:e0070ff187413aae541143bbcdd98ea3547b1fc749bcc0c54d6f9953ba21690f_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:cb13e29cf535cc082373527f427d88b3628fe647e748184e8641c140b84b51a6_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:10358537dac3f45ab842cc2ffe35866bba1b7c930037fae060c1dc56c208fd1a_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:3a0b9b9e484a3b5eb3133116e5bde9b632a8264523c6c677ff7c375b41a551ca_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:6a6bb6f9a57bc5484a3c3e3223606719c963b9939b07d40c2c7eaccf97ce6a20_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a6416cc5df0daff1955c278bfff158753ab91550893dd5f6c9ed1eae3edc1fc1_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:2e1b327b96ce3b897f25133b0d119fbe671e499dee2483e72f5953cc85947a06_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:55fcafa328306145fb515af001c4a6b1424e61e77f7598a738670e8e08ca1226_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:cd69b10f89d87fa81dfe6e2ac09b6d952c9c3bb8d7552ced62a18b04d66752bf_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-node-agent-rhel8@sha256:efa3abda7dfbc249c451ef3402ec794f18c7ffa6d0578d8aa4632dc5b81f0112_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:3fbd07f8ecd52c7bef5b8bd4ec4e83654e2be335449cac5f71f59df7edc8afeb_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-ebs-csi-driver-rhel8-operator@sha256:d4b2e0682d15ae445a112765eecb7ca5ec7bc3b8e86aea2e58ccde62f76400c8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:15aa989d3131186367f893d88ccc4eeb13ec246fa3536268d9d9bbc22c996d3f_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:1a4f777963acf754bd457982b4a95a24b3779bb87a019a3ee252b33abb1c20e7_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:b60762e60e1eb47785a3ccb5a60d2f520044ec90f74565919638b90b8465cdfa_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-installer-rhel8@sha256:e1918416621b741720e6d2f5df0490b2d042ed661bd1234109a4e160a1668af8_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-rhel8-operator@sha256:2fc16cab540d6cb1008fa99aa83b831e9c4d85d257c66a3a34f31f50b986e089_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-baremetal-rhel8-operator@sha256:3f36b4379c06ed8e3626f0be0c1d8186fdfbb658b11a95ebfe1cf8fe5c959dd1_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- +147 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:9c92b5ec203ee7f81626cc4e9f02086484056a76548961e5895916f136302b1f (For s390x architecture) The image digest is sha256:dbc768473b99538c15a35ea1be7ff656a6ac01e5001af4fac117c51f461c6054 (For ppc64le architecture) The image digest is sha256:dc4bab40680fb4ed84665abc34aefef5e0689eafef1c878776c3685ddaa759d5 (For aarch64 architecture) The image digest is sha256:5415fb0c33370014b9be83bc3120cc9d35a95922b2e93e218cac603e4179717a All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (53)
- selfhttps://access.redhat.com/errata/RHSA-2023:3304
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-12-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178358
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2183169
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188523
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2203008
- externalhttps://issues.redhat.com/browse/OCPBUGS-11294
- externalhttps://issues.redhat.com/browse/OCPBUGS-11302
- externalhttps://issues.redhat.com/browse/OCPBUGS-11336
- externalhttps://issues.redhat.com/browse/OCPBUGS-11353
- externalhttps://issues.redhat.com/browse/OCPBUGS-11387
- externalhttps://issues.redhat.com/browse/OCPBUGS-11432
- externalhttps://issues.redhat.com/browse/OCPBUGS-11775
- externalhttps://issues.redhat.com/browse/OCPBUGS-12363
- externalhttps://issues.redhat.com/browse/OCPBUGS-12461
- externalhttps://issues.redhat.com/browse/OCPBUGS-12722
- externalhttps://issues.redhat.com/browse/OCPBUGS-12770
- externalhttps://issues.redhat.com/browse/OCPBUGS-13082
- externalhttps://issues.redhat.com/browse/OCPBUGS-13083
- externalhttps://issues.redhat.com/browse/OCPBUGS-13085
- externalhttps://issues.redhat.com/browse/OCPBUGS-13086
- externalhttps://issues.redhat.com/browse/OCPBUGS-13127
- externalhttps://issues.redhat.com/browse/OCPBUGS-13138
- externalhttps://issues.redhat.com/browse/OCPBUGS-13150
- externalhttps://issues.redhat.com/browse/OCPBUGS-13155
- externalhttps://issues.redhat.com/browse/OCPBUGS-13162
- externalhttps://issues.redhat.com/browse/OCPBUGS-13170
- externalhttps://issues.redhat.com/browse/OCPBUGS-13222
- externalhttps://issues.redhat.com/browse/OCPBUGS-13312
- externalhttps://issues.redhat.com/browse/OCPBUGS-13321
- externalhttps://issues.redhat.com/browse/OCPBUGS-13410
- externalhttps://issues.redhat.com/browse/OCPBUGS-13427
- externalhttps://issues.redhat.com/browse/OCPBUGS-13497
- externalhttps://issues.redhat.com/browse/OCPBUGS-13531
- externalhttps://issues.redhat.com/browse/OCPBUGS-13563
- externalhttps://issues.redhat.com/browse/OCPBUGS-13591
- externalhttps://issues.redhat.com/browse/OCPBUGS-13598
- externalhttps://issues.redhat.com/browse/OCPBUGS-13683
- externalhttps://issues.redhat.com/browse/OCPBUGS-13692
- externalhttps://issues.redhat.com/browse/OCPBUGS-13731
- externalhttps://issues.redhat.com/browse/OCPBUGS-13742
- externalhttps://issues.redhat.com/browse/OCPBUGS-13783
- externalhttps://issues.redhat.com/browse/OCPBUGS-13828
- externalhttps://issues.redhat.com/browse/OCPBUGS-13887
- externalhttps://issues.redhat.com/browse/OCPBUGS-13888
- externalhttps://issues.redhat.com/browse/OCPBUGS-13959
- externalhttps://issues.redhat.com/browse/OCPBUGS-1598
- externalhttps://issues.redhat.com/browse/OCPBUGS-2290
- externalhttps://issues.redhat.com/browse/OCPBUGS-3160
- externalhttps://issues.redhat.com/browse/OCPBUGS-3166
- externalhttps://issues.redhat.com/browse/OCPBUGS-7147
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3304.json