RHSA-2023:4276MediumCVSS 6.5

Red Hat Security Advisory: DevWorkspace Operator Security Update

Published
July 25, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2023-3089 — openshift: OCP & FIPS mode

🎯 Affected products10

  • Devworkspace 1.0 for RHEL 8
  • devworkspace/devworkspace-operator-bundle@sha256:0090f19f2409c98b61dea57f905d355591ea5a554bf89e1d5accea6830b38be6_ppc64le as a component of Devworkspace 1.0 for RHEL 8
  • devworkspace/devworkspace-operator-bundle@sha256:1600c0fd5a6810f02ccb1440f5e03731b38891983d2a2fb13aa332bbc433eeaf_amd64 as a component of Devworkspace 1.0 for RHEL 8
  • devworkspace/devworkspace-operator-bundle@sha256:1c1c2245d70ad787b537bcdde2742d39dd1171809d5b459ffea82630da9a51a9_s390x as a component of Devworkspace 1.0 for RHEL 8
  • devworkspace/devworkspace-project-clone-rhel8@sha256:2d4e1ecf7d0a9968b84d1453838a23619d8d0be32b2352275b5931e070e90c42_s390x as a component of Devworkspace 1.0 for RHEL 8
  • devworkspace/devworkspace-project-clone-rhel8@sha256:3bd91ebeab17e83e2e2477211c4a113808549dbd5b59fdc35fd2ec5c8e2a8ecc_ppc64le as a component of Devworkspace 1.0 for RHEL 8
  • devworkspace/devworkspace-project-clone-rhel8@sha256:d41c9571370906141c551246fc22ad16d716bf3f4bc183b90c280e4e435d9a15_amd64 as a component of Devworkspace 1.0 for RHEL 8
  • devworkspace/devworkspace-rhel8-operator@sha256:41a0aaa72619f526934d08cd8191ea998cabc58b1bea8b8fcadd7bdb0fe173e7_amd64 as a component of Devworkspace 1.0 for RHEL 8
  • devworkspace/devworkspace-rhel8-operator@sha256:94ba245d62074146b89252df5cc0d6456e674ed324e8ebec72c8f9821b6fbca8_ppc64le as a component of Devworkspace 1.0 for RHEL 8
  • devworkspace/devworkspace-rhel8-operator@sha256:e4ab2900e371c2533e28ec6a587e08a8143ef95cde2d8003a3490b0c4b23b152_s390x as a component of Devworkspace 1.0 for RHEL 8

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected packages as soon as possible.

🔗 References (6)