RHSA-2023:3342MediumCVSS 8.2
Red Hat Security Advisory: OpenShift Container Platform 4.13.4 CNF vRAN extras security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2020-16250 — vault: Hashicorp Vault AWS IAM Integration Authentication Bypass
🎯 Affected products6
- Red Hat OpenShift Container Platform 4.13
- openshift4/topology-aware-lifecycle-manager-operator-bundle@sha256:bacc5365ec4112c87eb0b76e8f9d575168aa99632d19640dccf4d4bd0e5af598_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/topology-aware-lifecycle-manager-precache-rhel8@sha256:bcb9b47340a555aa21e4b7e33f5686c52d177afd911ccc1b12c014c91de013e2_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/topology-aware-lifecycle-manager-recovery-rhel8@sha256:f2188c046127b960582b54e7922e553147c9f973f3d064367332c75ce5536c09_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/topology-aware-lifecycle-manager-rhel8-operator@sha256:f95b1ec957cf9af6085c1c64d7e389163632c47eccc520078c056e31958053e8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ztp-site-generate-rhel8@sha256:ce030e999b4b19e26dd5c4712cdbee820bfefcb9950889b4b2bff3472750fd4c_amd64 as a component of Red Hat OpenShift Container Platform 4.13
✅ Remediation
For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2023:3342
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2167337
- externalhttps://issues.redhat.com/browse/OCPBUGS-13161
- externalhttps://issues.redhat.com/browse/OCPBUGS-13700
- externalhttps://issues.redhat.com/browse/OCPBUGS-7422
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3342.json