Red Hat Security Advisory: OpenShift Container Platform 4.16.0 security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2023-29483 — dnspython: denial of service in stub resolver CVE-2023-45289 — golang: net/http/cookiejar: incorrect forwarding of sensitive headers and cookies on HTTP redirect CVE-2023-45290 — golang: net/http: golang: mime/multipart: golang: net/textproto: memory exhaustion in Request.ParseMultipartForm CVE-2024-3727 — containers/image: digest type does not guarantee valid type CVE-2024-24783 — golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm CVE-2024-24784 — golang: net/mail: comments in display names are incorrectly handled CVE-2024-24785 — golang: html/template: errors returned from MarshalJSON methods may break template escaping CVE-2024-24786 — golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON CVE-2024-28176 — jose: resource exhaustion
🎯 Affected products200
- Ironic content for Red Hat OpenShift Container Platform 4.16
- Red Hat OpenShift Container Platform 4.16
- buildah-2:1.33.7-1.1.rhaos4.16.el8.aarch64 as a component of Red Hat OpenShift Container Platform 4.16
- buildah-2:1.33.7-1.1.rhaos4.16.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- buildah-2:1.33.7-1.1.rhaos4.16.el8.s390x as a component of Red Hat OpenShift Container Platform 4.16
- buildah-2:1.33.7-1.1.rhaos4.16.el8.src as a component of Red Hat OpenShift Container Platform 4.16
- buildah-2:1.33.7-1.1.rhaos4.16.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.16
- buildah-2:1.33.7-1.1.rhaos4.16.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.16
- buildah-2:1.33.7-1.1.rhaos4.16.el9.ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- buildah-2:1.33.7-1.1.rhaos4.16.el9.s390x as a component of Red Hat OpenShift Container Platform 4.16
- buildah-2:1.33.7-1.1.rhaos4.16.el9.src as a component of Red Hat OpenShift Container Platform 4.16
- buildah-2:1.33.7-1.1.rhaos4.16.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debuginfo-2:1.33.7-1.1.rhaos4.16.el8.aarch64 as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debuginfo-2:1.33.7-1.1.rhaos4.16.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debuginfo-2:1.33.7-1.1.rhaos4.16.el8.s390x as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debuginfo-2:1.33.7-1.1.rhaos4.16.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debuginfo-2:1.33.7-1.1.rhaos4.16.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debuginfo-2:1.33.7-1.1.rhaos4.16.el9.ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debuginfo-2:1.33.7-1.1.rhaos4.16.el9.s390x as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debuginfo-2:1.33.7-1.1.rhaos4.16.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debugsource-2:1.33.7-1.1.rhaos4.16.el8.aarch64 as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debugsource-2:1.33.7-1.1.rhaos4.16.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debugsource-2:1.33.7-1.1.rhaos4.16.el8.s390x as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debugsource-2:1.33.7-1.1.rhaos4.16.el8.x86_64 as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debugsource-2:1.33.7-1.1.rhaos4.16.el9.aarch64 as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debugsource-2:1.33.7-1.1.rhaos4.16.el9.ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debugsource-2:1.33.7-1.1.rhaos4.16.el9.s390x as a component of Red Hat OpenShift Container Platform 4.16
- buildah-debugsource-2:1.33.7-1.1.rhaos4.16.el9.x86_64 as a component of Red Hat OpenShift Container Platform 4.16
- buildah-tests-2:1.33.7-1.1.rhaos4.16.el8.aarch64 as a component of Red Hat OpenShift Container Platform 4.16
- buildah-tests-2:1.33.7-1.1.rhaos4.16.el8.ppc64le as a component of Red Hat OpenShift Container Platform 4.16
- +170 more not shown
✅ Remediation
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.16 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.16/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2024:0045
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.openshift.com/container-platform/4.16/release_notes/ocp-4-16-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262921
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268017
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268018
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268019
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268021
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268022
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268046
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268820
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274520
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2274767
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0045.json