RHSA-2024:0832CriticalCVSS 8.1

Red Hat Security Advisory: OpenShift Container Platform 4.12.50 security and extras update

Published
February 21, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients

🎯 Affected products150

  • Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:2152f2f921881cd0f66d40a26ef5c3d62f8cf5d49a09599d4fabf019cce60bc2_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:d982f38289fc291a9d0d9426b39c66ab4ad9d3f26f47f99622b2ef63f906d0fa_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/cloud-event-proxy-rhel8@sha256:ef5e3baa7f71e5f3337faa874739e1faedc15eb5c0fae78b89aac250fb24e50b_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/dpu-network-rhel8-operator@sha256:8f9e02dbfe2d4100ea23d95a4aac7bcad1f21e700272d2e354d20050224e21f2_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/dpu-network-rhel8-operator@sha256:c5990fe23267d1932a264ef82b982b375d8d109b2ef64946add91c415482698d_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:17b3349258e8e0c147b3bb9c0fb21fb6024ab0c9d3b32a80da413d06e94f85ae_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:a638a116ff4763aaef3b78061cdc75c8eee0dec18e961606a978ce855d5650b3_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:db98c92c4632096aef995bdf6a61cc55bd89bb735908ccd443a12870f8ffca2b_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall-rhel8-operator@sha256:fd1c8a5d08718c9bd48980706559d7378a77a7bbc86af3c6a5224311d4eee4c9_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:435567559194424927f9ad45428ad22a422adaebb723addea2f50b8daa672ae3_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:e6d3a0b8b510a67ab9dce9ec19360fc24a997d160fff51ae3b40fbd6ae51aa77_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:ec3244ab3a56b3e9a2f4f433d87e4aeadaca87eb5c9b8baf053d2bb93c734b6f_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ingress-node-firewall@sha256:f78b3491cdb55dbf8e1c6d59fb29301ea417112e740b178d2b9f0e9788db5e75_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:1f757de860fe5041c3d35d0df2e05840adf73629edcbe3d2f51b429c599594d4_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:6c36400a55dcc746c3d3ab67bcd7cb43b6c0eaaf8039bb0cd208ed07f2cc2f13_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:a2b69d17468b96929ab9a0f684898910765eeaec3c0585e0ec2e430acf5904d2_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/kubernetes-nmstate-rhel8-operator@sha256:b1cbc99bcef7c01600902a721c8952cfc383a92815392b065097b7797ba1b67e_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:05ccc38f1dbbdbf6a52293ac963425973a4087b609ba7dbba4dbd85adfce2b47_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:134738cf0013c6e44f8db7b6646d541e4f91822ea5f11fd51e7e8dedbcfd8dba_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:1a1a2966d52e5d5673cec5b85f05ba10de797aa6f03c25bb47dae2fe2cc8bbce_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/metallb-rhel8-operator@sha256:e8880cbd854419125406e14ac47ac471441181038861b48b1df5258e35735219_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-ansible-operator@sha256:69148fd64f03a6da8494fa4acc2bbbddff3d8706df5aef25ed8c1a15cb5a3e63_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-ansible-operator@sha256:862f97807f72efce7e3c335f9c4b1479576e659fae1fd9cf7749cef9c751c1d5_s390x as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-ansible-operator@sha256:88c07dfca1f96b60571bb78e490ab77e7aebf24956d828379213fe3bf4f2814b_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-ansible-operator@sha256:a499b1ef10724922a7531106ad339af24e709ae86860a3cbcc46a04d616bff36_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:1ccfe541696f03ced651ecde314052943c6ac9eaefe394ebb756840bc57a64bb_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-efs-csi-driver-container-rhel8@sha256:b97ba0bfb1c0d61ddb28edb8cf6fb8a46810df77e230031cf5ba0e37f0daa064_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:6329322b2d81b43e6df79ae16646e354aff103da526e1ce88321c6a75abe6c58_arm64 as a component of Red Hat OpenShift Container Platform 4.12
  • openshift4/ose-aws-efs-csi-driver-rhel8-operator@sha256:934bb6adccb0ef59a536ef0d7f41989be1aacbffde745027e9924db0c3126031_amd64 as a component of Red Hat OpenShift Container Platform 4.12
  • +120 more not shown

✅ Remediation

For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.

🔗 References (5)