RHSA-2023:4582MediumCVSS 9.8
Red Hat Security Advisory: Release of containers for Red Hat OpenStack Platform 17.1 director Operator
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-21235 — github.com/Masterminds/vcs: Command Injection via argument injection
🎯 Affected products5
- Red Hat OpenStack Platform 17.1
- rhosp-rhel9/osp-director-agent@sha256:197160a2e744eb53a6e152407c825cc3e2a88830a4feba01aabbd11d9b16e404_amd64 as a component of Red Hat OpenStack Platform 17.1
- rhosp-rhel9/osp-director-downloader@sha256:61159eadd71ed20f274f22007347860a5569db386e8c70da6cb4cbcaf3a4bc59_amd64 as a component of Red Hat OpenStack Platform 17.1
- rhosp-rhel9/osp-director-operator-bundle@sha256:c41549c229cb7af7034a0711f715be1b75695830cdcf7c524230508a5f938717_amd64 as a component of Red Hat OpenStack Platform 17.1
- rhosp-rhel9/osp-director-operator@sha256:af6ac5429c7243d9faf4e13b6c337b2e8beb17adc7c44beaac74787c3b71ebf2_amd64 as a component of Red Hat OpenStack Platform 17.1
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2023:4582
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_openstack_platform/17.1/html/release_notes
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215019
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215317
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218299
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221326
- externalhttps://issues.redhat.com/browse/OSPK8-701
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4582.json