RHSA-2023:4694MediumCVSS 9.8
Red Hat Security Advisory: Release of containers for OSP 16.2.z (Train) director Operator
🔗 CVE IDs covered (1)
📋 Description
CVE-2022-21235 — github.com/Masterminds/vcs: Command Injection via argument injection
🎯 Affected products5
- Red Hat OpenStack Platform 16.2
- rhosp-rhel8/osp-director-agent@sha256:435b11c52edc98da6f15e21da9fede79825a97b2ac6e5df738d7af77fadb4453_amd64 as a component of Red Hat OpenStack Platform 16.2
- rhosp-rhel8/osp-director-downloader@sha256:7ab88acf3a7c1568b05ec08564a0930cc43a5dcf21ec774bc785bb50545f2b86_amd64 as a component of Red Hat OpenStack Platform 16.2
- rhosp-rhel8/osp-director-operator-bundle@sha256:ebeb0f15e68d0200420e6b6b013116e550e8110c3038e4cc37e73dd38d3ed248_amd64 as a component of Red Hat OpenStack Platform 16.2
- rhosp-rhel8/osp-director-operator@sha256:1d06f2bdb1d80b843bc6f5c9b55009c003cb35cec8416c4da9983c48681769b5_amd64 as a component of Red Hat OpenStack Platform 16.2
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2023:4694
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_openstack_platform/16.2/html/release_notes
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2215317
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218300
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228513
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2229173
- externalhttps://issues.redhat.com/browse/OSPK8-735
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4694.json