Red Hat Security Advisory: OpenShift Container Platform 4.10.63 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-3089 — openshift: OCP & FIPS mode CVE-2023-24540 — golang: html/template: improper handling of JavaScript whitespace
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.10
- openshift-tech-preview/metallb-rhel8@sha256:0daa9b56a9c14cf1031a5b45b8c015129918c9f724fb94e9f89a3e326d99ab50_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- openshift-tech-preview/metallb-rhel8@sha256:7638ae5c8359a36c1dfa34371ec50d5ca9377aeb9e23585f9ba6d6967a5bf1a2_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift-tech-preview/metallb-rhel8@sha256:ab5f70eef0096549814edeb194801cca8ba7796865cd95eb96b01ffa8a28bdd2_s390x as a component of Red Hat OpenShift Container Platform 4.10
- openshift-tech-preview/metallb-rhel8@sha256:c36ad291ba9b721fce25cfcb25ab72bb4bba6b91cc05c88f6364355781338b93_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/bare-metal-event-relay-rhel8-operator@sha256:916f4b1703d7c7740e57bdeaa6ce1d8580c29e169d72e1287c336f77b46f7bdc_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/baremetal-hardware-event-proxy-rhel8@sha256:6fc15d07aba677cc1d108e91e14d892fa432c0ee07d6149bc8f7657dfe07b880_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/cloud-event-proxy-rhel8@sha256:13da75bcd35667815823b21f3d72562c2451d9a8a44ce2e2542e94d6686c5b9d_s390x as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/cloud-event-proxy-rhel8@sha256:6a55a51308d881f4b96828fb801fe14d111ca07e3657741033dc45ba1d6945dc_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/cloud-event-proxy-rhel8@sha256:b592f56ba6a63e2ec01c104a43eeb19195563bdfd9db69b9ccc8f02c8229cb7b_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/cloud-event-proxy-rhel8@sha256:f6e201e825b9875e54480f3dba115fc28e467a20f1d34029190c9b890d1755c7_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/cloud-network-config-controller-rhel8@sha256:322c8b5b66db6e51c760a4fd3c7332888e62ae143b43b65b9e29454aea9057be_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/cloud-network-config-controller-rhel8@sha256:61bdb3d64ae7583657f4eef00ad59b0e2d4e0d2fcb4adcd7b24e8a761af9d925_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/cloud-network-config-controller-rhel8@sha256:681bd0dfa98519bff6ce1699bc08b55fb50e1afa79fe7d340c411d4165d21d8e_s390x as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/cloud-network-config-controller-rhel8@sha256:688c50f9bb4c738ea617aa20345ba774d49be9f1b66ea3bb6c01ee942b8203a7_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/dpu-network-rhel8-operator@sha256:6c068543eb577780c10e45bb5b1730f47654c0077e6cc7727ea2d9bc95632e5c_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/dpu-network-rhel8-operator@sha256:894eb8df52ebe4542edb7b339bf27557b2d676434fa0b4dfed30e3d9f75a8e05_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/driver-toolkit-rhel8@sha256:96a1421059a7836617c1bfbd4aa7b5b5da25b721cb6df46b298493f775217987_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/driver-toolkit-rhel8@sha256:bd5a2f0fbe17038289a07a72f96cf383fb9dcc9cb056330e799aa931985f3798_s390x as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/driver-toolkit-rhel8@sha256:cf84fbae4dc0ac440d3e5adfa0f3c199df8beb387a674a1a8b3071d20f5ccb4f_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/driver-toolkit-rhel8@sha256:ea989f687c667ccda96a6df70041390f15f7e7c15741ffd18c1ad1f3baade21c_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/egress-router-cni-rhel8@sha256:402a48087c47b95e6c7c3016c332ac636fc619076a31ad230332f5ef6f40b6fe_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/egress-router-cni-rhel8@sha256:563d51485377a84423dce117702c1d454a90377b813efbdb4e16075dfc82b2a2_s390x as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/egress-router-cni-rhel8@sha256:db6888184936ea6d697ccb9ccc4505f4d21409ba8a1f32ad7fff08d9fb08d9eb_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/egress-router-cni-rhel8@sha256:e9961ea79db48f81f749051628d131d0fccae403283dc97667d5ccbe5de3e3cb_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/frr-rhel8@sha256:55d207672991e9f59c25ad2b3fe1d7922fd7874c3a485a9ae69832f551285c22_amd64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/frr-rhel8@sha256:7f458c227b2e3ca1fd0664a8922657be5b46ba6e1a33edff40dc59f2a265fd69_arm64 as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/frr-rhel8@sha256:bcb555533f19e61272a5602ae02fa87d767bf3a8fd0cc2f8ef4fc233a85b5834_s390x as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/frr-rhel8@sha256:cb69d17095151f86c4290dc008d2c1e5faf353d519081800c0918fdeba5bebee_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:031d537c032826183041cc305d180bf2cf730fb6d9f22bee2be7707372aa72a9_ppc64le as a component of Red Hat OpenShift Container Platform 4.10
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.10 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.10/release_notes/ocp-4-10-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:340091aefa0bba06bbb99cc58cb1f2b73404c832f72b83c526b8e7677efbecef (For s390x architecture) The image digest is sha256:9b4d9a313b4d6e94a5c707ee49592cb59fafa164c6c9a10da4e231ac7002e49d (For ppc64le architecture) The image digest is sha256:f23cdf8bc612b196450558c9197d0c66042647d460d88d84e1158b29fa4fc614 (For aarch64 architecture) The image digest is sha256:3d796d605ff5c83d09d73c268702f018bb16c6fc526433b302b095581b08d83b All OpenShift Container Platform 4.10 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.10/updating/updating-cluster-cli.html Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected packages as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2023:3911
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196027
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2212085
- externalhttps://issues.redhat.com/browse/OCPBUGS-12751
- externalhttps://issues.redhat.com/browse/OCPBUGS-14359
- externalhttps://issues.redhat.com/browse/OCPBUGS-15178
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3911.json