RHSA-2024:0740CriticalCVSS 8.1
Red Hat Security Advisory: OpenShift Container Platform 4.13.33 security and extras update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
🎯 Affected products149
- Red Hat OpenShift Container Platform 4.13
- openshift4/dpu-network-rhel8-operator@sha256:5c10f8885d20a4c23f7bddc7ec02b8331a821d3b26c8f25782138c6978fb5b6b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/dpu-network-rhel8-operator@sha256:8cdc5cfb0457253e5c5dfc8fda5ec86ffbdd4da28bbe4a5ebc98132fc846b64b_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:6896419a0ed5e34e09d09c3707f9c30610ac1342961e36e4118c48cffc0a1cf2_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:8dc01ad2d76a4d15a58216d9ec18e18a448804df66f124793b43d5256d420f59_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:b8d6c5b0c1db9db0b3201535b8c0b9b16619971edb12651afabc66d9a80483d2_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall-rhel8-operator@sha256:d9bb4b9581362876de0353297d78e21ce0d66954b62fb3945e1c9d4a0825b8f3_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:412e3633fc5c438e2913c745ac4e015e64b5daeb6b08b630ded98463a1f1a7dd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:5b412539dd1425d2627e4ce4fd3d61cb8f731d1ce5a33d4f08b7a4efeafa5fc9_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:934c680653a5a0f538ad71435dd8609bb9fbbf2bdead0d88ac578d905a56a05d_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ingress-node-firewall@sha256:ef935b5f945e50ba8f8e046c5ea676e1e2720f3baf992139fa2bbc83c7d5a689_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:52dbf66cabe5b4c02e44d1d9ffed973a54a4d25ffafd78836211fecad59e3019_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:5faa884f605922e2d9c8b62883736b1ea278c427bc9f8da39054f8a7279b58b9_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:742fe4d62827781a85ed8ee33a5a9f5d2bff45709e7809f1a3ad75e1c1124f05_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubernetes-nmstate-rhel8-operator@sha256:8a123c8cbbf95f1b0048937687017cc44528d828df3bcdaa71c9b32327b03dd3_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:4f90782ba2065fdb86e740a756be13b3cc7ce718e93dade1e196225cf8ebdef9_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:5d772dac269a64a3a30c2592bb923db4e94ccc2c28de171100426101bad07a86_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:70180338d37c343aff59821823420a55b12f34c4f424b0eb64baeb060788568a_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/metallb-rhel8-operator@sha256:a679cbf86fdbe6b452e4210ffb0956208333c658fe66d92f2fa23e9f8d915c92_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-ansible-operator@sha256:6383f07098eda13fd2d79a9c32e18d48c5b78826009b41ba3eb6295228679792_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-ansible-operator@sha256:d0e866d65ea8225673370e64259c1232c337da5a87b667a6030ba8735a28dd39_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-ansible-operator@sha256:daf074413081e02aab67bed84ee0d9d3996ffef11ca32a620a79dede0c17e5f6_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-ansible-operator@sha256:dbc02b18dcc74c66322ae6875b3f0c3dc3e3bee574791b1451a6cad07a2699ab_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:7d5060ca07739f906d28a7db4991be40db2f12d36da228cc8f6292949250f5f7_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:f3fb4cbb46725421f9f68d4576ba4532dc3ba92ba3c733af11020ea049511788_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:6686f5d73c1452c93da25676e918f8db9a6834767d86e87da642a635f2c8f44c_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:f8b5c3864b0ac2e749a3af9119f013dc4b63c7b24b0d02e48271511cca356753_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cloud-event-proxy-rhel8@sha256:0b92dab47b3a7cc2fbd2a1e9ac0f151d2601b10252479ff023f4a16786290bde_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cloud-event-proxy-rhel8@sha256:22cde4f04bf42b1f48fbd41e3838a76e19ed5140255c3537cc5215bac805b27e_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-cloud-event-proxy-rhel8@sha256:89a115120bed14561712319750a203bde32711536b9afcd74bb43eccdec28522_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- +119 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2024:0740
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0740.json