Red Hat Security Advisory: OpenShift Container Platform 4.11.44 bug fix and security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-3089 — openshift: OCP & FIPS mode CVE-2023-24540 — golang: html/template: improper handling of JavaScript whitespace
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.11
- openshift-tech-preview/metallb-rhel8@sha256:2dd0946a3f0022a5650d86264e84f519ef24a3aaca9e19052583657a984055bd_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift-tech-preview/metallb-rhel8@sha256:60e1981718123ecb4ac96bf3cd1a9e1c1655e43708280838fbb3af4070b094e9_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift-tech-preview/metallb-rhel8@sha256:70d62f9b3e211c2624fe4d55f430cbf45c342904a381a64a931f77a125b6533c_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift-tech-preview/metallb-rhel8@sha256:acead0d920d53acf69ade1f416ad8eb3703bd23e582aa26f5cb7668b534136c4_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-event-proxy-rhel8@sha256:190fc9d2af960c365c1d8aa0c3bd07efa3c78e26c222d22acfdd76b1062b1d71_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-event-proxy-rhel8@sha256:4e277a68d9ce4fb8727da7e876a674c92cda7e1d75397b3758d592da712704a9_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-event-proxy-rhel8@sha256:964ef9dba67cfa6a8090da025e0d4d8528fd2aa45554fde761d4e94e4d3349b2_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-network-config-controller-rhel8@sha256:15d929e5bb7fd0a1b91197b6ea427fe9563d4e8a706ed70cb5b2531c7cba7d31_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-network-config-controller-rhel8@sha256:19ed58474bd35ac668ea389ae10b1a4685c838c4fa1e835f98284613c8d1989f_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-network-config-controller-rhel8@sha256:ae1838f10c80db10e71c270754d0d7a121b3746edfc864306309370520b661d8_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/cloud-network-config-controller-rhel8@sha256:b1371d74ccd62342f8b0543e905d6bcea86ee0bb581248cb5d3f203e1843a338_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/dpu-network-rhel8-operator@sha256:306b1fe0c19090290585225ea3ea74a7b95285ef385f95181ef370ee878b6639_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/dpu-network-rhel8-operator@sha256:d243d85640874906e71dfac80b6e53568abb1944dfd9d16504b47150906b17da_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:0c23bcd7172476fb4e0e26c9d72dd31d65269935070f8a010ba75657156f6c25_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:1fb99c64b63ec160f444fb9f028235149a50733a2444feac4d5c69353043cfed_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:48480fb112d179f80afa134379fe73ee9c4612a1879472b15e489560fbfdc9d0_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/driver-toolkit-rhel8@sha256:b0d4510b62b7cb1cd1d35b729fbed3e22bf15abb73602b29f0c8d1f8324c1852_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/egress-router-cni-rhel8@sha256:31b3ecf0a931189d2155b49e09960c14dcc173ec2b4544a6643b22189728b831_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/egress-router-cni-rhel8@sha256:3479719fc504b39f453cbde0bd5694f329f946dbdac49f417b673604a51cfbef_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/egress-router-cni-rhel8@sha256:39a682e76cb1830ef288d4019fb4d1ade12f5826475cdc7d23265d2e0c74892c_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/egress-router-cni-rhel8@sha256:9082685d2c633b8f66189988f87c432eac2ca8d4d24c611a5480d3c4168f7945_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/frr-rhel8@sha256:0bcecdbeac4cd0d88a0c7c10902d63994f1880b11fb075e21f821f645e6a0897_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/frr-rhel8@sha256:1ddf1d325aadbeb24666464eb0f56063528a7b13bf8d1a7c13c69a012495d02b_s390x as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/frr-rhel8@sha256:5849f5ffdbc2cae77f681a241a81a6cf7507013b12685d7efc6a2b0690d32dd6_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/frr-rhel8@sha256:ee6eac6f3989f52ef3dcd2d13159a53ead52d95954d970bb26f1b18961941c7c_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:0b0d8798cade428fd28854f0cfcbaf5207e9149a41f941c159bbba0685d3f2c3_arm64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:10911015c9a2cf3a711df2f6d5f92319e4653e0f5cb7f54f6bbcc411d9bcc531_ppc64le as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:8dd92fa222f76ae7d470e2099611fa4f21f7cefbee4630fbb65422242039ed86_amd64 as a component of Red Hat OpenShift Container Platform 4.11
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:b8acd14953898262138d25c764c3f0443934e75c294302a090a7f9adead56c50_s390x as a component of Red Hat OpenShift Container Platform 4.11
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.11/release_notes/ocp-4-11-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:52cbfbbeb9cc03b49c2788ac7333e63d3dae14673e01a9d8e59270f3a8390ed3 (For s390x architecture) The image digest is sha256:8e25fe8123b744a1e7ae48b1d02cb989387168c6bc3eef8a47ee7ee13157c25f (For ppc64le architecture) The image digest is sha256:9d9ee02572038ccc4750e416c2acb4a222bfc4fcca63a3595ff63685304d0e53 (For aarch64 architecture) The image digest is sha256:e26acde99c69074890e2eefc4ca89506e3dd7426c049a7ff02734cabfa3be42a All OpenShift Container Platform 4.11 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.11/updating/updating-cluster-cli.html Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected packages as soon as possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2023:3915
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2196027
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2212085
- externalhttps://issues.redhat.com/browse/OCPBUGS-14004
- externalhttps://issues.redhat.com/browse/OCPBUGS-14355
- externalhttps://issues.redhat.com/browse/OCPBUGS-14413
- externalhttps://issues.redhat.com/browse/OCPBUGS-14456
- externalhttps://issues.redhat.com/browse/OCPBUGS-14457
- externalhttps://issues.redhat.com/browse/OCPBUGS-14654
- externalhttps://issues.redhat.com/browse/OCPBUGS-14686
- externalhttps://issues.redhat.com/browse/OCPBUGS-14746
- externalhttps://issues.redhat.com/browse/OCPBUGS-14931
- externalhttps://issues.redhat.com/browse/OCPBUGS-15150
- externalhttps://issues.redhat.com/browse/OCPBUGS-15151
- externalhttps://issues.redhat.com/browse/OCPBUGS-15361
- externalhttps://issues.redhat.com/browse/OCPBUGS-4812
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_3915.json