RHSA-2023:4290MediumCVSS 6.5
Red Hat Security Advisory: OpenShift sandboxed containers 1.4.1 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-3089 — openshift: OCP & FIPS mode
🎯 Affected products8
- OpenShift Sandboxed Containers 1.4
- openshift-sandboxed-containers/osc-cloud-api-adaptor-rhel9@sha256:dddb09a228b578d122dc7e2418b0f7e7012706ec98e6660753b926a305a1d99d_amd64 as a component of OpenShift Sandboxed Containers 1.4
- openshift-sandboxed-containers/osc-cloud-api-adaptor-webhook-rhel9@sha256:128fec3b462e781635876b4e43dec3dc2ef787e6128ad245ed78f2196a4a798e_amd64 as a component of OpenShift Sandboxed Containers 1.4
- openshift-sandboxed-containers/osc-monitor-rhel9@sha256:77fb428dfbf4d2dfa993cae7b005d69d5b35feaa585ffd25d34062998403462e_amd64 as a component of OpenShift Sandboxed Containers 1.4
- openshift-sandboxed-containers/osc-must-gather-rhel9@sha256:66fd690e92a853bfd9a4d03a64e0b7b75ef142c3c9f570b404fb93c0e58385b7_amd64 as a component of OpenShift Sandboxed Containers 1.4
- openshift-sandboxed-containers/osc-operator-bundle@sha256:7a28671f1fe44e66ef519c8540d709969c7b3ff291e0c8ea8547588cf0e1bd6e_amd64 as a component of OpenShift Sandboxed Containers 1.4
- openshift-sandboxed-containers/osc-podvm-payload-rhel9@sha256:365893d3bc80f43bdebfb2f34898a8531a80aa63d9c43bdb6dd33eb2ac6505bd_amd64 as a component of OpenShift Sandboxed Containers 1.4
- openshift-sandboxed-containers/osc-rhel9-operator@sha256:65337250abfb5347dcf5b8bf8e1113ffbda214da990c958bcb2d7bb69c99fb53_amd64 as a component of OpenShift Sandboxed Containers 1.4
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected packages as soon as possible.
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2023:4290
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2023-001
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/openshift_sandboxed_containers/1.4/html-single/openshift_sandboxed_containers_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2212085
- externalhttps://issues.redhat.com/browse/KATA-2212
- externalhttps://issues.redhat.com/browse/KATA-2299
- externalhttps://issues.redhat.com/browse/OCPBUGS-15175
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4290.json