RHSA-2023:4730MediumCVSS 6.5
Red Hat Security Advisory: OpenShift Container Platform 4.13.10 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2021-20329 — mongo-go-driver: specific cstrings input may not be properly validated
🎯 Affected products169
- Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:0f810eee76322040f500037df6a4396bbf0d87b10c71a17994e40d8a223e4cd5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:2305918e859d2ea4d609c38946d4612009e72201bce4c5a8f86ac08648d1e08a_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:d9293cd8470846d087e71409a37763e7af264384ae3b947a4287eb51da67496d_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift-tech-preview/metallb-rhel8@sha256:de0cdc69537082018f99b890d223e036f67b35df25de2ac25f0e44b87765fac6_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/dpu-network-rhel8-operator@sha256:ba0a58563776146d75340e193499bd811efc097f711b7dc7665403a094dbc605_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/dpu-network-rhel8-operator@sha256:d7cd610bf7909a5162f4cad5762bd1685f58b61aacd917ff9c26dc47157be329_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:2ddd4cb70a4072e7476db256cd74104aadd78c59bf481b37b1c0880ff016e9fd_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:3db6792a0faa8aa026552f1d1a79a92037827ed6252c046e561feca5b894e2e0_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:c4567564b21a2eff0bc7a063098c2b58014590705ec2c58782051926c93c09a2_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/frr-rhel8@sha256:c85443e9f3d891b7780c3e31f3a5a104cb7c26e565cfd6973e0ee971d921848d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:2a9cf1838cea2f203e2011e232cefd8f3114793e16d6cd6bd67545cb2c45cd3d_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:a54ca93e525b07369bfb1658c52f2a1f0d8410d252dd5bd377e6ecf82cfe1b92_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:dc1439bbe40d9102b4f3b7903cd27876fe6c25b6a03ad542fba4827b788c2605_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:f64a46dad6ae9bfbeec5486226064a54aed7d5a3d0ba6c0e5ae8dce28955600d_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:0d48bd259d2efb5b87798f1cf74501539ffe1b149ac073189eee0ab8b88d1004_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:376e5a18c3a975839c171e80f76fef9dc519f9bf06ca56e18be8f994ac785d2e_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:c7d12302e4f9f2d77d4a401e2f5ba75ba3d8b51d3eb019e7f320f9bee4538f55_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:f93b73cacf4aac462fbdd22a47747760443a21a7f9e572bac0a69c00ef58b991_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:0d5aebf94a87c48e42a8bb0462f37120a9b5624d1c76ecbd00426b83f0f39b96_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:db73017c52f514e5630573489f5ded9d84cec8ad7c8033a84c7328c7d074a05b_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:fa8a87737acd9a5642d7c0f7156e2e57dde5e8241402b7fbf11efe2a46222680_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:fe0445e88fc69383bb2119425211cb4147a6051cd4ffab6cbcda981f626b71b5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:1c0776329f175ca96950225d3301859e75e4dc955cc3b6279ccebc92c0529028_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:325f0f5a451d0921b234231ef2d52526c98569078921424aedfe1ce94e557799_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:c3622aa93d8da3c638ebbd3af1348c257249aca107d30993cf666850ee9f494a_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:f42c283c2fce63d42402d78529781ccc7103672e3a94ed1a4ad9864530c20be1_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8@sha256:0f810eee76322040f500037df6a4396bbf0d87b10c71a17994e40d8a223e4cd5_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8@sha256:2305918e859d2ea4d609c38946d4612009e72201bce4c5a8f86ac08648d1e08a_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8@sha256:d9293cd8470846d087e71409a37763e7af264384ae3b947a4287eb51da67496d_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- +139 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2023:4730
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1971033
- externalhttps://issues.redhat.com/browse/OCPBUGS-14954
- externalhttps://issues.redhat.com/browse/OCPBUGS-15830
- externalhttps://issues.redhat.com/browse/OCPBUGS-17425
- externalhttps://issues.redhat.com/browse/OCPBUGS-17525
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4730.json