Red Hat Security Advisory: OpenShift Container Platform 4.13.34 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:1e482c54202850b8c4e296b38a566a39f77c03feac8e49b720795707b4cde6e7_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:69343929cd0131e36579f109769cc4a380635b19e4e2f02448e6e05280b20a5b_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:7ba99ed161ac820b68bff6faa8e521ad34723e6bbd26628b0be7fb9f75a641bf_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:9c44532b93f9a5ea4ad97fc5e02c1cf74a56445e84c71f33558c0f37b471bbb8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:43f3937b9ec236f2e4dd71237420fdc79e8e569290ca356eba34c8fb8a85076b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:c2308a70788d78d6dd90ac801d85cc017141fb1a8067c481cdebcb9387f4f70f_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:c6d2e0bb79528ba1509be44b732518d9735969938ff81ff5bacdc1a2d0184f1a_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:ef4d7c54e1ad722206c826a4cc81f642bd40f6813f90f9dd6d19e7655d47a504_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:6ec02ae28220f2fddf5a989e6c84247937bcd3efebe3e8a680b76a8547523c11_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:96270977ad6a59aff8568272b876aa63e309646412a800a014d5cd857404a873_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:a298fe0b3f3b11d2b00d0e5a38f4a651efeb8052d5b53a1f0ff0c5103bf324af_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:ec0c97390c4a0ebb11ecb2109b1b90f9ead98c01d13fff26886b57dcd0e6b706_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:2a2beb122de1a39fddd1330280f5b64c77c7b58db2b248c5fb4f14ae928c3c03_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:506189c34acb1879bb5c75d91f7c25881ee5f9041bfd6cfe69c298392e37928f_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:9280d569d65c9443f9993e97112dc4f2d11146c04541bbaaa034209a4579f8ab_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:9d1daf6df91e4675081da44ad07bc7a39b57b151fdc094442a7277a316e80c6c_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:60f6d8055c9f579e34b1a3e11ad806a7ec3d4fdd3a064c5b803e15b9be5508dd_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:32333fe2da1d2504862993cbbbbef00ef90c0f20c73babb6cccd27d6e8e24d48_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:3374eddc135a593b47fafe2742596bccdca6278e244c3cdf9d6f6e6a24859f61_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:a7732fb7852d9bd1547d9addaba63ac7641b3f87f62abec73e406c8d240345d4_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:d2aa0c07d4b82d63b897f1758249787506a939b756d8c527369cf03d88875928_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:3348f1ec160f8b319090c99df541c52888677af924e3ea8b840b1a3369aa1edf_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:4d872868e2b77bdce631d954f469d53adb66ecc3eac4cab25c680a0ed8613031_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:507449a152ecf178f5f82e0ce2bd556ec3e0d81cf9314bd2867807f5f2c92f82_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:c56941eb6e017a993e8c7d9d6c27d8f894b7684f3d88083cdc6b5db18d339b5b_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:0a775a33601fe0bf231e6eb73d6acc0386eafd63726a76791d19a565a0149167_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:801a7038097e257dd7e63d0a7585959888f12b3f42b7804bfd7bc4a97019d170_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:86adb655d41c29a18f81a6e9ce39d32fbce6d081ccaa46d8ed0aa4e4c9319cbd_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:be07dc3550f62fdcdc5d64ec6766c017ff61c6c2574db96e6387f617db886265_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags The sha values for the release are: (For x86_64 architecture) The image digest is sha256:04081f0cdc3a98eb9b705aceb86d4a035f7e6ccf6d9d10621776d53134f81c33 (For s390x architecture) The image digest is sha256:ca025a3ba9de59089b7278263115bd54a4d7164e48b9fa856c6f3688f62dae82 (For ppc64le architecture) The image digest is sha256:f42073e4296bd8e8dcf1b3ccf3a9a0213eac6039a1393d56bd34514606e09900 (For aarch64 architecture) The image digest is sha256:64a6652bc3ee1eeaa4020ec7ea73e7484b398aa98144bcc4774cbb1358375027 All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift Console or the CLI oc command. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2024:0845
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- externalhttps://issues.redhat.com/browse/OCPBUGS-28740
- externalhttps://issues.redhat.com/browse/OCPBUGS-28899
- externalhttps://issues.redhat.com/browse/OCPBUGS-29190
- externalhttps://issues.redhat.com/browse/OCPBUGS-29243
- externalhttps://issues.redhat.com/browse/OCPBUGS-29301
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_0845.json