Red Hat Security Advisory: OpenShift Container Platform 4.14.26 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2024-28180 — jose-go: improper handling of highly compressed data
🎯 Affected products200
- Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:43df12939393a5e2d2d16f5d648ce5c2bd176eb9cbbe10d5d62824a04a26ceef_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:5e6b343dafee386c61828b70c2082f7a4890502c6a78786aa7fe95de42a9e84f_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:ad16b3622d53b11b8caec656061a2bfe3475b0082c161bb74d9c3bb8ee7f4cdf_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/cloud-network-config-controller-rhel8@sha256:f16b029ddbc2be4f35a0b584242cde6ec440aef625f116537b63adcc8e83c85b_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:44b8147c571c9928b86fa62f3664f7d4b97542af97d036daf60b54eec0f14c4a_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:577cd6aceeeaa592b609a615694ed5878b28f64bae48a7509a1a26e96abdab98_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:65fdd54fd57e9ffcf26e6f12f55091907ce53187f0d76bb566e6803768804e2e_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/egress-router-cni-rhel8@sha256:95d0ea5ba861ca58662d92fec674a8fdf3cb9a6a23a489ad00dea66636eb3089_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:57224c9223a6d599a7d75b2c422e8e34083acab043222955e8a0c6d1b8db2f85_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:76e1eb85d63f16dd8ad1ee9d0850b58ba606a6a2325dda40ed5e74c051ec3c1d_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:9bc65e6debd0e0b4fbbe166f6b8ccd3d228736a94cb67898aa051b20f5013845_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/kubevirt-csi-driver-rhel8@sha256:de0f1a07b48413a0040bb6a7973c944a01f2413c229833dd1bdfb446814e948e_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:494866f9b0e087349369b8089788ef59d8a9230d753a50595c9a4f76fd7c072e_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:54f29617b9b0bbba1c74d58ca2b37f74e5dee2ccb45f25afe3643ee8971c2d71_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:64b2c173f31398b5ae0df7ae727466c0013fc7787e58841475feb392f5d3abc3_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/network-tools-rhel8@sha256:693872b298f32fd166aa8242bbd27cd2fddb771098c28c1d669ed0e3d0e84f42_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:06247c0e42ef05ff55e060e58cff5d7ab8753bd4867ef2568bd6cc5dcde97ab3_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:bd672b164eb0e65c2b6cbf092d0ccebe002a18026fba82a934ad9141f1fb9c1a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:faa0cab6bc5a8221c06bf8eb5b68f06862426d60bbef6702fe001486f6c9f28f_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/oc-mirror-plugin-rhel8@sha256:fdc3307c790cd1d4d6770019f35fd457950d44e5d0ebf20a94803ef3986f868b_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:1bed634efcd4583e7d59c774d287cb4007553f57dfdaab00bacf423ee9a7c3fc_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:ae77ae09866c6729082b1f196a2c01c8c276926764224a4bb14365952d5cee44_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:e3b60c522fcd6185cc9b79a5970dabcf027320c69d45916c2465d803e33f8945_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/openshift-route-controller-manager-rhel8@sha256:e580d74324b7caea2ba2ce8c8b302e7fc46d895a6ad1846a81e1d6a9af03e3dc_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:12866ee463b5246bdb7f64259330a6f92366f76b136abdf725f79fdbeb00425a_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:2c6d0aa9b937b85eaeb5b4edfd0c0f76e88cbdbdda89ab974a772babdb0b3dea_ppc64le as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:6de5b303042035e7667e9c0cebfeed22e17ad6c7f36ef508575d5df2e8693502_s390x as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-api-server-rhel8@sha256:a72b747d67414d4c413b82834601daec253cc76c8b76d7c634c74c4099a8d321_amd64 as a component of Red Hat OpenShift Container Platform 4.14
- openshift4/ose-agent-installer-csr-approver-rhel8@sha256:3a049f6b92ce8fd6a126b8191c8c4314b489f8bbdad82467e601607f5d1b0ca0_arm64 as a component of Red Hat OpenShift Container Platform 4.14
- +170 more not shown
✅ Remediation
For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.14/release_notes/ocp-4-14-release-notes.html You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are (For x86_64 architecture) The image digest is sha256:4fe7d4ccf4d967a309f83118f1a380a656a733d7fcee1dbaf4d51752a6372890 (For s390x architecture) The image digest is sha256:a4ad0c43b02c2157627cf885e6e8efde1d04d9424602ae05859fcc26dd55e377 (For ppc64le architecture) The image digest is sha256:da98ac542a8d4e77d2c617f30122abf64141d64d8be7a12fd7a423e67f636b46 (For aarch64 architecture) The image digest is sha256:4e5134eafb41bc6800d6caef24b915060c255ffcd1c01db2e77c9bbf52226946 All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.openshift.com/container-platform/4.14/updating/updating_a_cluster/updating-cluster-cli.html Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (16)
- selfhttps://access.redhat.com/errata/RHSA-2024:2869
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2268854
- externalhttps://issues.redhat.com/browse/OCPBUGS-14373
- externalhttps://issues.redhat.com/browse/OCPBUGS-30153
- externalhttps://issues.redhat.com/browse/OCPBUGS-32104
- externalhttps://issues.redhat.com/browse/OCPBUGS-32319
- externalhttps://issues.redhat.com/browse/OCPBUGS-33039
- externalhttps://issues.redhat.com/browse/OCPBUGS-33110
- externalhttps://issues.redhat.com/browse/OCPBUGS-33365
- externalhttps://issues.redhat.com/browse/OCPBUGS-33389
- externalhttps://issues.redhat.com/browse/OCPBUGS-33452
- externalhttps://issues.redhat.com/browse/OCPBUGS-33462
- externalhttps://issues.redhat.com/browse/OCPBUGS-33467
- externalhttps://issues.redhat.com/browse/OCPBUGS-33563
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2869.json