Red Hat Security Advisory: OpenShift Container Platform 4.13.41 bug fix and security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2021-4294 — osin: manipulation of the argument secret leads to observable timing discrepancy CVE-2023-49568 — go-git: Maliciously crafted Git server replies can cause DoS on go-git clients CVE-2023-49569 — go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients CVE-2024-1139 — cluster-monitoring-operator: credentials leak CVE-2024-1725 — kubevirt-csi: PersistentVolume allows access to HCP's root node
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:064e53b50d101edb81dbc0269a1ddd3dfb53c9a6d147930caf3864414c984cb7_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:1208f9278d4dc37f7364f9c2e0961c257abb4ec6aee46d1c275753d21a7ea020_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:70d9860f407904da564fcb440c099a02b30e6cbc2ba41b03992a0d7aedf7362a_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/cloud-network-config-controller-rhel8@sha256:84e9ba434c0c72fb05c14cec55a78a77d41b856594cb72824587e3b34b0236cd_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:2421e498039bc6118e902cef9531af6c90a3cacbe51ecb4efd37476c25caadad_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:3eb0a2ed49d53c49e1eb78ea1de4f0e72e09ebeffac06ecf8d9b2cdf39d13027_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:5570e313a221f3fdb547b5b8481b783e5c6fac5fa46cc272b1045d0b17b55ce4_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/driver-toolkit-rhel9@sha256:f3dd23ed11d307c89369c02c3047d45de1d78c7403b1657f0dda4ccd60dce75b_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:9ebccf66e1d50554bc03a6fada52cb377dc69a6d38b1ebbf436ee8d4cc5f879d_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:db0b77eb759b785539b8b360142cb1acb02ec62013e586f215ad6c02e35636f0_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:e96e3ca93d0d4ec0a84bc72727d9b1a6c1eddb730591fc60d6cdfa25b6a9d200_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/egress-router-cni-rhel8@sha256:ee926885074ecf8ba1ab49a1cb0adad6cd943ae82fc92e33dcb7a4ce93adc270_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:1e1d60dcafdcf59f50cc4d6f6a6907bc54a984908b0c85f676a3a37c87abb670_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:5c023b0e1f3ce1b1af1e9689d4e4b56ea372ba847f9ec742b7b824ae0ad4bab5_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:a736e373732e14e9dd2895b30e686bcac7686d28adbde2b66a777ba9b15ba910_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/kubevirt-csi-driver-rhel8@sha256:e087e1c48f57e36910423e9d267cbeb083dc0ae67bf52779b5aa2e6928249b7d_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:0ba8b302889cf363de77d186ff0f99e9491376c107104c3a0af4392ed3cecc90_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:237d467654027ff2daf361975e7e3a1622620e4f041083247096cfa6490eb448_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:4a0051aac00b5875e03c472cd3e77825b7f147eea37e351ba33561c66fa98907_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/network-tools-rhel8@sha256:f64ece6d9add0db1a7d44cd5070638b5036a075e147fa10e3b5dc8de69854b87_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/oc-mirror-plugin-rhel8@sha256:c1ee4e883b4a0646fd4a850442cc89428e98b582845d6696c1ba59d7e266eab8_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:2db357cc4d03944bcbef40954e541813655fda0ecf1b86b8d1fc25f1b88abe99_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:3194f27e1cfdd73ae62ba2ca43f62efb23ccf9b1cca3f8f551997a92b329fa63_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:904c0bea4175fb5fae31f3238d65b5d1dbbb3f81d23f666cb853775d04d57063_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/openshift-route-controller-manager-rhel8@sha256:dbcd949085d061a8533f1bbc1d59a3419f7de814679c84dfe493228a4f83ca27_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:034e37daa7a2c6fd0493019c8dfa42efb9a051f2502261f51cc18d5326503829_amd64 as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:20c3c10f3f936597ee63669d7a9d1025cd10ec40b1f315565747c3722a2dd080_ppc64le as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:8d899b3f78e9ee3bc73b235448ce479c69ebec7002b49c4845ce578eb8248cfd_s390x as a component of Red Hat OpenShift Container Platform 4.13
- openshift4/ose-agent-installer-api-server-rhel8@sha256:c93ead264183fb65b0a2d38dd71b3bb979936118f8a7e3064801acec7f7773a3_arm64 as a component of Red Hat OpenShift Container Platform 4.13
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.13 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.13/release_notes/ocp-4-13-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:dbb8aa0cf53dc5ac663514e259ad2768d8c82fd1fe7181a4cfb484e3ffdbd3ba (For s390x architecture) The image digest is sha256:421f1d408713576cd597aeabdeefb2cad6c6d4c1f40e0a88e9026911fb69aaaf (For ppc64le architecture) The image digest is sha256:00283cbb7dceb54be3bea4f7d2b7877eac7dadcd952f0e4b0c3d95cf761f03bb (For aarch64 architecture) The image digest is sha256:b6395664a18f7fe6ae8faf57a6be0490ffffa12b71dfa42e9515f91baa407a6f All OpenShift Container Platform 4.13 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.13/updating/updating-cluster-cli.html Workaround: In cases where a bump to the latest version of go-git is not possible, a recommendation to reduce the exposure of this threat is limiting its use to only trust-worthy Git servers.
🔗 References (19)
- selfhttps://access.redhat.com/errata/RHSA-2024:2047
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156871
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258143
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2258165
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262158
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2265398
- externalhttps://issues.redhat.com/browse/OCPBUGS-22979
- externalhttps://issues.redhat.com/browse/OCPBUGS-25922
- externalhttps://issues.redhat.com/browse/OCPBUGS-28784
- externalhttps://issues.redhat.com/browse/OCPBUGS-31077
- externalhttps://issues.redhat.com/browse/OCPBUGS-31505
- externalhttps://issues.redhat.com/browse/OCPBUGS-31595
- externalhttps://issues.redhat.com/browse/OCPBUGS-31702
- externalhttps://issues.redhat.com/browse/OCPBUGS-31936
- externalhttps://issues.redhat.com/browse/OCPBUGS-32143
- externalhttps://issues.redhat.com/browse/OCPBUGS-32334
- externalhttps://issues.redhat.com/browse/OCPBUGS-32359
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2047.json