Red Hat Security Advisory: OpenShift Container Platform 4.12.56 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2023-39326 — golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:77d6a1bd98092df13b7b9bb193316c5f8650f9db3c0ee5417d0cde5b95908d2a_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:7f2b03b46a28528edf83fbfd556b4d06ab222de342f35a2e5382cfa1129a7784_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:99315bb556108f3b5a693f4956361769b974fa11dbeece098d54c6dcce1682ed_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:d63a40491f7601fb45dff89133f0a418e8fb30fea1d8b8c1bc231d30b7edfb15_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:2524a9dd1de5892d4415006a9e0d5c1e8215cf0f2e48d797892214007462f043_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:91209407fad295d89a9a2d7cf7875a540b9d5f6d867b1bb1882403ebb4a0f8bd_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:f462eb48332514957165a8031253dda0f0041d644889e1b704a55035790aab2a_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:f5546ac5f41ed033516cd950635c2030ff65ffb66a50d1b969862103748fc1fa_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:1942121d3fd18c6e21a5db524b64e9341e99c4e9677be7290e7f11d261ccf515_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:19650d274fe106d4107f6ab200471c1974ab259e7547876b3aab4502d1a742a7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:4754739f70e468a315b060ccebee64b8f18d1080caca25ef750fa58e86ffc398_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:f3418874bbe4b79f15205bd731a99fcf5308c608b51ac273d61e76809d756d01_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:1b6dd430d033fcc6b215e1fd2431a82adb108b414fe268220645e58145ae6726_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:468f319f61faf31317f26a13d0e40ebb8a188fcc9f3ef9e994c27a2cdbcc2aaf_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:73916efba08b82b02a2c6610dd15e94c1b2c42c050408ea3118215cfac0ed6ed_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:b9e02c355cd12416c45f8f0d7e209b05db2afa22380c950a8c7dd357e22019b6_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:098ecbd830107af7d9148fc51908eb73195ec17b43b5ef1f5c627a3c16f38e9b_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:136b1734b022c8cdf14e35fc8824c3172c618a1e908a41920ca1024823410f7d_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:40630ef4fa019b719ae2d3ff8b2a4eaf15eabd8904c8db5f86fa9581769e906c_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:6c7830b4a2bebeb90fc7ecc2b6fb4630e2cf9ffc1e2b2d6346e5285a66bed98a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/oc-mirror-plugin-rhel8@sha256:5a21ff575c728f912b561a078be3af232120ce54a04ae3ff40b6e587b1b1d46d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:324a44009a1e81ea5fee715b116b22fb3fc5b713d254bf6dfb849e3f3473ba7d_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:495267c6e669bc10dfce6dd7ce58b42332921e2463269f18a0cdc576cc00d716_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:6dbbc838c16fb9fd035c943f854e822ff153a80d66b80023d894924224618cd3_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:c080ca141f7521979d34ac1ef40c1e9aee1906034d610324a8cc9ed71971699b_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:22a78e1fe0c2b3e7ce83eb08807eb135170f477677f6b55d92da073dc08ad6b6_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:52716ca5292df1d7cb883b160445ed2b713a0e94f3a7a62b9bd86e5f227849bc_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:bcf4743ba3b8051124a9aa0171e7769498a26c52801a0cae7ac2f0a26f77b869_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:faf3c9d53d89ff74a07d3b72c2374f33553f3231c8c997ff61e39025e12bf1cb_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:7446b0c3cc24c6d35c0d0fc968ef27f52da92c60f41951c0e646041db108169a (For s390x architecture) The image digest is sha256:0297188ad2936833b6b1377ca35276277d86fd614dfed8209fb1c06ccea4087d (For ppc64le architecture) The image digest is sha256:7c6bca201a245b790a2d122fb0e0717db2c9c95a2aa505e2db6fa3b16218e00b (For aarch64 architecture) The image digest is sha256:c8e7b64a4fa1145eeac395b4895fb60524f71f22eaffee0f69fd70e25b3bab16 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: No mitigation is available for this flaw. Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2024:1896
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2253330
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- externalhttps://issues.redhat.com/browse/OCPBUGS-30289
- externalhttps://issues.redhat.com/browse/OCPBUGS-30809
- externalhttps://issues.redhat.com/browse/OCPBUGS-30829
- externalhttps://issues.redhat.com/browse/OCPBUGS-30914
- externalhttps://issues.redhat.com/browse/OCPBUGS-32205
- externalhttps://issues.redhat.com/browse/OCPBUGS-32226
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1896.json