Red Hat Security Advisory: OpenShift Container Platform 4.14.22 bug fix and security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2023-3978 — golang.org/x/net/html: Cross site scripting CVE-2023-47108 — opentelemetry-go-contrib: DoS vulnerability in otelgrpc due to unbound cardinality metrics CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients CVE-2024-1139 — cluster-monitoring-operator: credentials leak CVE-2024-1725 — kubevirt-csi: PersistentVolume allows access to HCP's root node
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:0850923badfda8f7de1ca5944a5658ebf81b32d5304286d23fb37244955053c1_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:556e785a2126995b3aa755008e4ccb145f1238f8b2d80bb0c18e6ee23afc2aa2_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:66eecbd91cd592bddac3f503bba97f9e71afb016d060ac5571cd79de8cdc4165_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:c75e2eb0402f828b554a8430e345d91e5ba15c3a0557a2108deefe707853585d_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:259cbd840454c6d9030c21a5d24be0599abc4941cdd525a80f6eeb5d67e7908c_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:49938d0ec66c6cc24ea7415db33d0828d25b132935a158f8dd1002521684ecfd_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:92101ee14a2d05bddad27bb7bb4b7bb38fb5e3686c16fa0ae1350ed35260dcbd_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/driver-toolkit-rhel9@sha256:d02ef5c5544b276cb0c22be7d852359a31b39298dba1fdb0c5283cdf51c4ba70_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:4b46317dd95fc7691854116737b1aaf7fa452860b88d3df5079856f8af846d54_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:afbc037c329e3ae53541afe8c68385140e6efee09c4b3d2efafc47a08f0affb9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:bece039d316366865b6394785c0d15421bacc85e0c983c5a593e324d86128c18_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:c4c67169cf6ce36718420b78091f49c3353fb390a86193b3cb0719c740c9de24_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:03dbe4b0147159abefdfeeb5be2face9edb3dbca84ff1b1fee6ab21d49670920_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:0ea132b7a37b0c44abdd378089ecda1ac9cf25573335da3efed52a63fd66b916_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:1e327467bc9baa9b5ca5149151fc0bebf14e7cff36483b414ae97f289eb701c8_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:d62138b7f38d27486f27d6f6c571e742346e87b37edb5b853d04d2c660bc4836_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:0171c911dd26ccb06e2af7cb3f4e262e3846215c7791aeac96b2fc63478dfeb3_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:1c726afcb53e33913efc8f1b231fc5f895d244f98d3b3a16b2837ae483fbe652_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:a65117a5b4d349b88ff8b977f0fd894aaa635bdd595c6518be613dee689f0d50_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:af48778799fd7062b1f1d44e7d01daac36bd6d05b226ec94ec332ac0d8029e6b_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:33c09a5b37a17fc4bdd13e9023ec9cfea0e9e9cc3c2beaede8e3cb4ce171bcdf_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:3f59a4ee014a4789e7a30d58c0292bb9eb2f707e0b05bc3114b44a869b08f3d0_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:41ed8429926208c66524c79910314d7b28847715f80fd234f95972d4a25f4a40_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:ea07e8468f2cc03c48a0db8b32bd1e3e260d3a5ba679762d9885ff3dc170b5fa_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:7d90dedb67a1d4281b1be5ac78c6555002dfa5a50c4fe121f3e7613b9c44c2a3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:bf20bdac88ad3712651a82809ded2ae294c7887f8ce96381599e8371e6172d7f_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:db715697c78ed07c57e31329288b728e77b538cee8d040f17f689a348eef832d_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:e4ee0de87e415362c76060d919f8fb05c219134655011b47470889fbefe54689_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:25c85841035515addfb94665c660f45a97dd449db36ce112f75371714343c3df_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:7093fa606debe63820671cc92a1384e14d0b70058d4b4719d666571e1fc62190 (For s390x architecture) The image digest is sha256:784621b67af470153f02521237b8170fed3d58d31333b4b094cf30f6d657e40e (For ppc64le architecture) The image digest is sha256:6cedfcf05100b51d7dab8ac4c0ea8c06aac8989143a3d564daf5b8041120e3ae (For aarch64 architecture) The image digest is sha256:7c13402788d2e98964fa6e53b435b02b62d71769ce6c66fb4cf7d0116c7a33c6 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: As a workaround, use a view removing the attributes. Another possibility is to disable grpc metrics instrumentation by passing otelgrpc.WithMeterProvider option with noop.NewMeterProvider. Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2024:1891
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2228689
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2251198
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265398
- externalhttps://issues.redhat.com/browse/OCPBUGS-25145
- externalhttps://issues.redhat.com/browse/OCPBUGS-27108
- externalhttps://issues.redhat.com/browse/OCPBUGS-30898
- externalhttps://issues.redhat.com/browse/OCPBUGS-31487
- externalhttps://issues.redhat.com/browse/OCPBUGS-31504
- externalhttps://issues.redhat.com/browse/OCPBUGS-31648
- externalhttps://issues.redhat.com/browse/OCPBUGS-31669
- externalhttps://issues.redhat.com/browse/OCPBUGS-31677
- externalhttps://issues.redhat.com/browse/OCPBUGS-31731
- externalhttps://issues.redhat.com/browse/OCPBUGS-31844
- externalhttps://issues.redhat.com/browse/OCPBUGS-31862
- externalhttps://issues.redhat.com/browse/OCPBUGS-31885
- externalhttps://issues.redhat.com/browse/OCPBUGS-31886
- externalhttps://issues.redhat.com/browse/OCPBUGS-32112
- externalhttps://issues.redhat.com/browse/OCPBUGS-32137
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1891.json