Red Hat Security Advisory: OpenShift Container Platform 4.12.57 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2021-4294 — osin: manipulation of the argument secret leads to observable timing discrepancy CVE-2023-45288 — golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS CVE-2024-1139 — cluster-monitoring-operator: credentials leak CVE-2024-31463 — ironic-image: Unauthenticated local access to Ironic API
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:1d321389903eb9c3fe53ababafee159133afbdf8e308ab969e8fe1848c89e34d_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:7b51cebda169f5c098c3272bda0b6121206c86f777e0edbe4498809aeea57693_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:7da350f08b2799ca8ccf33f074d88e1d5b4ddc6fe045294fed51132392b814d2_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/cloud-network-config-controller-rhel8@sha256:b479067e956ee49d1b56839e37d1a462e124d726d6ad545b41695f0c15268386_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:30582df8c032105b8bc5edf8e15207364b6872b26ffe57edbaa2e05e3a341676_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:49ca171f1af55bd8b9afd138c833184cb1cf5c5651438ec5144b8d51ae84d83b_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:c38d3e76d47d87fae172b102c623e74a1c39a7c67ca04a03f1c5b7026751b51f_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/driver-toolkit-rhel8@sha256:d2211fe1c17cf56c2950786860251204a0e6c5f7987f5aeb73f41cc0a0574da7_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:110518c26f22ed9f48914a179a291c01bcc426a25c7a64a6d32f41b0f24045b2_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:186c0b7d3dc2f8eab577be6bde8dc669eddd66b33599a9c943f6ef41b99a483a_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:1d3c197e75489edbe969a979d3890aa6bb45784f7e56197913c2ee4887beb101_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/egress-router-cni-rhel8@sha256:7577fe0d56d9284c03acfdd8225a9783181827fa415df9945c3cb2ec7f332ff2_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:1e39b12aa9f52348e55e28614735e979bc95d884b650d6d955b8d6e2e68f2490_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:42375052d644ed940d037e0cfa7ae5ad6021eff6221828d02c0feb15a8ab3975_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:503e90137680af2c0ad09ab69984f361c443c3662b9125a7bce2d091081bf223_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/kubevirt-csi-driver-rhel8@sha256:d60017ce09c8eecfb6127981bda75405e2fa507a652baf1eea911c50dd47e5fd_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:1caee567cd57863c5e3815922c4721da57f9466614af6bf87716fcbc9d3091fa_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:3169314297bd133bff029e25259f7f54ea661d4481678fc2d1951b830539aec2_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:9fd0859be4f5f9a87a8f77733df3fe4c6149f91bbdd472604c18ac79ad22bb0b_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/network-tools-rhel8@sha256:c2e8bfd681120835d1c189c3d1df051df13d665b1861102c4a795bc924efeaca_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/oc-mirror-plugin-rhel8@sha256:4fa6e0a946de1bc46f99ba99070e33e0b0cbaea18607abc422d61c5666c4a63e_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:2dafe4a257261e6a5a49767f0ed8e30f32371ed463e967febe1f0a9d762e8ddb_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:36b0342eeb92c82dfba4d2fd188d04c828290b1185056b25a6199eea294bad1e_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:3c2aaf37e8ca25e3d27346a6d2fe241174704744ca1a0ccc96ea326b73fbcb45_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/openshift-route-controller-manager-rhel8@sha256:c6aa3dee2555e2d4aab96995ce061afa978fd50392f8805a3e4476a09ac522e6_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:2fcf5f7bf6e879907a291772cd76ac2ca38645a3c0f8dd071cc526f093cc7da6_s390x as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:4872bf172293e57f2afa6aaa6b80f2bd09cd88d2fed337cc3d8508f89a07fc47_arm64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:52217c68e207e69d6a41b58d71cee11ba00f935be88c5cbe05d283a4b8ec8460_amd64 as a component of Red Hat OpenShift Container Platform 4.12
- openshift4/ose-agent-installer-api-server-rhel8@sha256:bfeaa92d3a313e01f7dd4f659c1e748db7350f49e18810fd5de2ebac8a4df15e_ppc64le as a component of Red Hat OpenShift Container Platform 4.12
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.12 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.12/release_notes/ocp-4-12-release-notes.html You can download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests can be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:ebd20cd66e0bbb5bcd7d16559ff4856918b7172e29d6a7bd34d8cc49a556b8f7 (For s390x architecture) The image digest is sha256:7a18130347117b6c168a81a7311ba5eb74dcbaeafdb281d32d6a81254810d445 (For ppc64le architecture) The image digest is sha256:528a87f912c91861afa839b04b48fd6b8b79960d8872c8876c2de39821c74a39 (For aarch64 architecture) The image digest is sha256:0126ec3e0c154a2e8f45b92b8b41f8508d8a3c9ca096bb150c2bcc0740599b65 All OpenShift Container Platform 4.12 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.12/updating/updating-cluster-cli.html Workaround: In some environments where http/2 support is not required, it may be possible to disable this feature to reduce risk. Workaround: Below are two mitigations for this vulnerability: 1. Switch to using unix sockets for traffic between HTTPD and Ironic/Inspector (recommended). Set the variables IRONIC_PRIVATE_PORT and IRONIC_INSPECTOR_PRIVATE_PORT to the value unix. OR 2. Temporarily stop using the reverse proxy mode (set IRONIC_REVERSE_PROXY_SETUP and INSPECTOR_REVERSE_PROXY_SETUP to false).
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2024:2782
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2156871
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2262158
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268273
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275847
- externalhttps://issues.redhat.com/browse/OCPBUGS-30630
- externalhttps://issues.redhat.com/browse/OCPBUGS-31442
- externalhttps://issues.redhat.com/browse/OCPBUGS-32429
- externalhttps://issues.redhat.com/browse/OCPBUGS-32449
- externalhttps://issues.redhat.com/browse/OCPBUGS-33253
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2782.json