Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.13.0 security and bug fix update
🔗 CVE IDs covered (33)
📋 Description
CVE-2020-16250 — vault: Hashicorp Vault AWS IAM Integration Authentication Bypass CVE-2020-16251 — vault: GCP Auth Method Allows Authentication Bypass CVE-2021-3765 — validator: Inefficient Regular Expression Complexity in Validator.js CVE-2021-3807 — nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes CVE-2021-4235 — go-yaml: Denial of Service in go-yaml CVE-2021-4238 — goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be CVE-2021-43998 — vault: incorrect policy enforcement CVE-2021-44531 — nodejs: Improper handling of URI Subject Alternative Names CVE-2021-44532 — nodejs: Certificate Verification Bypass via String Injection CVE-2021-44533 — nodejs: Incorrect handling of certificate subject and issuer fields CVE-2022-2879 — golang: archive/tar: github.com/vbatts/tar-split: unbounded memory consumption when reading headers CVE-2022-2880 — golang: net/http/httputil: ReverseProxy should not forward unparseable query parameters CVE-2022-3517 — nodejs-minimatch: ReDoS via the braceExpand function CVE-2022-21824 — nodejs: Prototype pollution via console.table properties CVE-2022-23540 — jsonwebtoken: Insecure default algorithm in jwt.verify() could lead to signature validation bypass CVE-2022-23541 — jsonwebtoken: Insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC CVE-2022-27664 — golang: net/http: handle server errors after sending GOAWAY CVE-2022-30635 — golang: encoding/gob: stack exhaustion in Decoder.Decode CVE-2022-32189 — golang: math/big: decoding big.Float and big.Rat types can panic if the encoded message is too short, potentially allowing a denial of service CVE-2022-32190 — golang: net/url: JoinPath does not strip relative path components in all circumstances CVE-2022-38149 — consul: Consul Template May Expose Vault Secrets When Processing Invalid Input CVE-2022-38900 — decode-uri-component: improper input validation resulting in DoS CVE-2022-41316 — vault: insufficient certificate revocation list checking CVE-2022-41715 — golang: regexp/syntax: limit memory used by parsing regexps CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests CVE-2022-41723 — golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding CVE-2022-41724 — golang: crypto/tls: large handshake records may cause panics CVE-2022-41725 — golang: net/http, mime/multipart: denial of service from excessive resource consumption CVE-2022-46175 — json5: Prototype Pollution in JSON5 via Parse Method CVE-2023-0620 — vault: Vault’s Microsoft SQL Database Storage Backend Vulnerable to SQL Injection Via Configuration File CVE-2023-0665 — hashicorp/vault: Vault’s PKI Issuer Endpoint Did Not Correctly Authorize Access to Issuer Metadata CVE-2023-24999 — Hashicorp/vault: Vault Fails to Verify if Approle SecretID Belongs to Role During a Destroy Operation CVE-2023-25000 — hashicorp/vault: Cache-Timing Attacks During Seal and Unseal Operations
🔗 References (202)
- selfhttps://access.redhat.com/errata/RHSA-2023:3742
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/documentation/en-us/red_hat_openshift_data_foundation/4.13/html/4.13_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1786696
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1855339
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1943137
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1944687
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1989088
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2005040
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2005830
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2007557
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2028193
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040839
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040846
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040856
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2040862
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2042914
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2052252
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2101497
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2101916
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2102304
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2104148
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2107388
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2113814
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2115020
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2115616
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2119551
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2120098
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2120944
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2124668
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2124669
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2126299
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132867
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132868
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2132872
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134609
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2135339
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2139037
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2141095
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2142651
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2142894
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2142941
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2143944
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2144256
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2151903
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2152143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2154250
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2155507
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2155743
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156067
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156069
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156263
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156519
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156727
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156729
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2157876
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2158922
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2159676
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161274
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161879
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2161937
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2162257
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2164617
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165495
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165504
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165929
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165938
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2165984
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2166222
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2166234
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2166869
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2167299
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2167308
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2167337
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2167340
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2167946
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2168113
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2168635
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2168840
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2168849
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2169375
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2169378
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2169779
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2170644
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2170673
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2172089
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2172365
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2172521
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2173161
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2173528
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2173534
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2173926
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175612
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175685
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175714
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2175867
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176080
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176456
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176739
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176776
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176798
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2176809
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177134
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177221
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177325
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177695
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2177844
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178033
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178358
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178488
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178492
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178588
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178619
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2178682
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179133
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179337
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179403
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179846
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179860
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179976
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179981
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2179997
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2180211
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2180397
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2180440
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2180921
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2181112
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2181133
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2181446
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2181535
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2181551
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2181832
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2181949
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182375
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182644
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182664
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182703
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182972
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2182981
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2183155
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2183196
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2183266
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2183457
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2183478
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2183520
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184068
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184605
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184663
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184769
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184773
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184892
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2184984
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2185164
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2185188
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2185757
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2185871
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2186171
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2186225
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2186475
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2186752
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187251
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187736
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187952
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187969
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187986
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188053
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188238
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188303
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188427
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2188666
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2189483
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2189929
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2189982
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2189984
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2190129
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2190241
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2192088
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2192670
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2192824
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2192875
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2193114
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2193220
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196176
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196236
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196298
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2203795
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2208029
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2208079
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2208269
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2208558
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2208962
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2209364
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2209643
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2209695
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2210964
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2211334
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2211343
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2211704
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3742.json