RHSA-2023:4238MediumCVSS 6.5
Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.11.9 security and bug fix update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-3089 — openshift: OCP & FIPS mode
🎯 Affected products79
- RHODF 4.11 for RHEL 8
- odf4/cephcsi-rhel8@sha256:d4a2dad8e2975aed3c597dd717156e702d45e86b2ba447cbda5835a4c34aa024_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/cephcsi-rhel8@sha256:fb6a071dc91f21f5ff38590d802e679bf44f20dbabf4524cd3dd8264cf55ba89_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/cephcsi-rhel8@sha256:fc5994454ec74d505549bbc5a25c0950bbe86a6703d9e29bff1e89b98cb54dbc_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-core-rhel8@sha256:7557630c028281db03e00b92041b58c2c099ab4bdd828a2eba27a220d6090d0f_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-core-rhel8@sha256:7f7fa238e0420b703096893071015a7cd574aa526c794bfc2ab582fe15507258_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-core-rhel8@sha256:be61a7ff1a474b1516b42e0a7b5b7a02b2b43a5efe112e028b069dfa0264b411_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-operator-bundle@sha256:c4091f06ad38dff61088b239ffa6ba80fb7ea51ba1a92d25b0aae8dabc275af1_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-operator-bundle@sha256:d04e0db7ccb397a8f6b77825bafc6e95e7cb99167048df19190b668ddca48a15_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-operator-bundle@sha256:df945349171cb6cd45f6f2ee9ec3a569ae29a043f2928cb21d3cd22b8b716b94_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-rhel8-operator@sha256:1795a6286c4e8b6f2803d9b52a3662fdd14236395d6d9382ee1e788dd0d5d72d_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-rhel8-operator@sha256:22ab900ede86ae29ccb2be3b154e0434eae20582bb1599d1e35852900aaec41f_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/mcg-rhel8-operator@sha256:f0b56bce5c778dc317c0ee6d3cf498cd6e9cbaa6fdfc3b62f4da6f42c91490b1_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-metrics-exporter-rhel8@sha256:458543f7c9dcb7851c76411863499bbddd6e2f4608213f9695bda90f603f58aa_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-metrics-exporter-rhel8@sha256:ca35330d2b09f0df64ead38423b95d759f18f84715186b4ae4807e430e2b919d_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-metrics-exporter-rhel8@sha256:ea5822299be0e4ec4f0192fe1305e5aa1e4ea1a27b0c40a0fbaa76c6eb5adf68_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-must-gather-rhel8@sha256:3bae87a4567063ac7caab2799524f304e1b21e3daf68cbc7b9c3529ba23204eb_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-must-gather-rhel8@sha256:e5e506516e0c559c3d4e70ebac6e6f28a1aca88ac0972c760e83fffb43369b89_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-must-gather-rhel8@sha256:f771d3e484f30d7e4968fa92b00825184d13f96cb2f47c82ad0287fa9b407b3e_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-operator-bundle@sha256:2f95f8913a767f3f2dfe77e4bebf2e87dc79f8fb2256d4a7a1603df744622be6_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-operator-bundle@sha256:cf8db918e0653c7b01aea9a7834e538e5e59bdeb6f08cde8e1ab66c7dd68eaa2_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-operator-bundle@sha256:f6635a50797b0cb0baf5f1ce064b53e5b1d28872b7b005845e43f0fc25075347_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-rhel8-operator@sha256:2c409564639493ade6d7ad0bf0ee434c3c8ad25ed47cc684b5a35200356955f5_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-rhel8-operator@sha256:5e571589a9b056bf1085b9c250a12f72fdc7efe69a207114c4c14114ad90c350_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/ocs-rhel8-operator@sha256:8919465b70f19840b7ba0725e66963417fb05b9e0c91d93ba9f8db8a795ab557_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/odf-console-rhel8@sha256:32129e39f0b8cf943d7e0ca49743fefe9850c9a0d6428a513644c546aa62b5ee_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/odf-console-rhel8@sha256:4bd899603a1efae76f8aa42d7a806b2402caaa0edf2362671e98677e8caf6692_s390x as a component of RHODF 4.11 for RHEL 8
- odf4/odf-console-rhel8@sha256:9b3e279ef5702d5c9cb663d4e1482bdb2c2f6ba007fb7ab3d04bd500d277272e_ppc64le as a component of RHODF 4.11 for RHEL 8
- odf4/odf-csi-addons-operator-bundle@sha256:3bcc27e47ea4aac1b71b785cbf71b53e25872690631c6ebed061c9668e815445_amd64 as a component of RHODF 4.11 for RHEL 8
- odf4/odf-csi-addons-operator-bundle@sha256:ba69d808b425a2e7cc3641c2245db89c52f2c600455a4eab5aae050a34200ce1_s390x as a component of RHODF 4.11 for RHEL 8
- +49 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected packages as soon as possible.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2023:4238
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2209254
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2211594
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2212085
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213451
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2224268
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4238.json